cbcvebase.
CVE-2021-39675
published 2022-02-11

CVE-2021-39675: In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with…

PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.93%
92.4th percentile
In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-205729183

Affected

4 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
platformsystem_nfc>= 12:0 < 12:2022-02-0112:2022-02-01

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2021-39675 is a heap buffer overflow (out-of-bounds write) in GKI_getbuf() within gki_buffer.cc, enabling remote escalation of privilege on Android 12 with no user interaction required.
  • The vulnerability is classified as a Critical Elevation of Privilege (EoP) affecting only Android 12 (AOSP), referenced under Android bug ID A-205729183.
  • The vulnerability was patched in the Android February 2022 security bulletin; detection/response teams should verify Android 12 devices are patched to the 2022-02-01 security patch level or later.
  • ·CVE-2021-39675 exclusively affects Android 12; no other AOSP versions are listed as impacted.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.