CVE-2021-39633Improper Restriction of Operations within the Bounds of a Memory Buffer in Google Android

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 92.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateMar 14

Description

In gre_handle_offloads of ip_gre.c, there is a possible page fault due to an invalid memory access. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150694665References: Upstream kernel

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Debianlinux/linux_kernel< 5.10.70-1+3
debiandebian/linux< linux 5.14.6-1 (bookworm)

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2829-f4q2-487p: In gre_handle_offloads of ip_gre2022-01-15
OSV
CVE-2021-39633: In gre_handle_offloads of ip_gre2022-01-14
OSV
CVE-2021-39633: In gre_handle_offloads of ip_gre2022-01-01

📋Vendor Advisories

3
CISA ICS
Siemens SIMATIC2024-03-14
Android
CVE-2021-39633: Kernel2022-01-01
Debian
CVE-2021-39633: linux - In gre_handle_offloads of ip_gre.c, there is a possible page fault due to an inv...2021
CVE-2021-39633 — Google Android vulnerability | cvebase