cbcvebase.
CVE-2021-39648
published 2021-12-15

CVE-2021-39648: In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information…

PriorityP415medium4.1CVSS 3.1
AVLACHPRHUINSUCHINAN
EPSS
0.16%
5.8th percentile
In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-160822094References: Upstream kernel

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.10.9-1 (bookworm)linux 5.10.9-1 (bookworm)
linuxlinux_kernel>= 0 < 5.10.9-15.10.9-1
linuxlinux_kernel>= 0 < 5.10.9-15.10.9-1
linuxlinux_kernel>= 0 < 5.10.9-15.10.9-1
linuxlinux_kernel>= 0 < 5.10.9-15.10.9-1
linuxlinux_kernel>= 0 < 4.4.0-222.2554.4.0-222.255

CVSS provenance

nvdv3.14.1MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.1MEDIUM
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.