CVE-2021-39657
published 2021-12-15CVE-2021-39657: In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information…
PriorityP417medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.15%
5.0th percentile
In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194696049References: Upstream kernel
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.10.12-1 (bookworm) | linux 5.10.12-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.10.12-1 | 5.10.12-1 |
| linux | linux_kernel | >= 0 < 5.10.12-1 | 5.10.12-1 |
| linux | linux_kernel | >= 0 < 5.10.12-1 | 5.10.12-1 |
| linux | linux_kernel | >= 0 < 5.10.12-1 | 5.10.12-1 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.4MEDIUM
vendor_debian4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-39657: linux - In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds...
vendor_debian·2021·CVSS 4.4
CVE-2021-39657 [MEDIUM] CVE-2021-39657: linux - In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds...
In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194696049References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 5.10.12-1)
bullseye: resolved (fixed in 5.10.12-1)
forky: resolved (fixed in 5.10.12-1)
sid: resolved (fixed in 5.10.12-1)
trixie: resolved (fixed in 5.10.12-1)
GHSA
GHSA-rpgq-c954-jmg6: In ufshcd_eh_device_reset_handler of ufshcd
ghsa_unreviewed·2021-12-16
CVE-2021-39657 [MEDIUM] CWE-125 GHSA-rpgq-c954-jmg6: In ufshcd_eh_device_reset_handler of ufshcd
In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194696049References: Upstream kernel
OSV
CVE-2021-39657: In ufshcd_eh_device_reset_handler of ufshcd
osv·2021-12-15·CVSS 4.4
CVE-2021-39657 [MEDIUM] CVE-2021-39657: In ufshcd_eh_device_reset_handler of ufshcd
In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194696049References: Upstream kernel
OSV
CVE-2021-39657: In ufshcd_eh_device_reset_handler of ufshcd
osv·2021-12-01
CVE-2021-39657 CVE-2021-39657: In ufshcd_eh_device_reset_handler of ufshcd
In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-15
Published