CVE-2021-39657

Aliases:UBUNTU-CVE-2021-39657DEBIAN-CVE-2021-39657
Modified
Published: 15 Dec 2021, 18:06
Last modified:04 Aug 2024, 02:13

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.4 MEDIUM
v3.1 (nvd)
EPSS Score
0.15% LOW
0% probability +0.13%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

15 Dec 2021, 18:06
Published
Vulnerability first disclosed
04 Aug 2024, 02:13
Last Modified
Vulnerability information updated

Description

In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194696049References: Upstream kernel

CVSS Metrics

  • v3.1MEDIUMScore: 4.4CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.15% Percentile: 5%

Techniques & Countermeasures

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • debianlinux

    < 5.10.12-1 | < 5.10.12-1 | < 5.10.12-1 | < 5.10.12-1

  • ubuntulinux

    all | < 4.4.0-204.236 | < 4.15.0-141.145 | < 5.4.0-67.75

  • ubuntulinux-aws

    < 4.4.0-1087.91 | < 4.4.0-1123.137 | < 4.15.0-1098.105 | < 5.4.0-1039.41

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1039.41~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-fips

    < 4.15.0-2041.43 | all | < 5.4.0-1069.73+fips2

  • ubuntulinux-aws-hwe

    < 4.15.0-1098.105~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1112.124~14.04.1 | < 4.15.0-1112.124~16.04.1 | all | < 5.4.0-1041.43

  • ubuntulinux-azure-4.15

    < 4.15.0-1112.125

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1041.43~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde-5.15

    < 5.15.0-1114.123~20.04.1

  • ubuntulinux-azure-fips

    < 4.15.0-2024.27 | all | < 5.4.0-1073.76+fips1

  • ubuntulinux-bluefield

    all

  • ubuntulinux-dell300x

    < 4.15.0-1016.20

  • ubuntulinux-fips

    < 4.4.0-1057.63 | all | < 4.15.0-1057.65

  • ubuntulinux-gcp

    < 4.15.0-1097.110~16.04.1 | all | < 5.4.0-1038.41

  • ubuntulinux-gcp-4.15

    < 4.15.0-1097.110

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1038.41~18.04.1

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-fips

    all | < 5.4.0-1067.71~20.04.1

  • ubuntulinux-gke

    < 5.4.0-1037.39

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.4

    < 5.4.0-1037.39~18.04.1

  • ubuntulinux-gkeop

    < 5.4.0-1011.12

  • ubuntulinux-gkeop-5.4

    < 5.4.0-1011.12~18.04.2

  • ubuntulinux-hwe

    < 4.15.0-142.146~16.04.1 | all

  • ubuntulinux-hwe-5.11

    all

  • ubuntulinux-hwe-5.4

    < 5.4.0-67.75~18.04.1

  • ubuntulinux-hwe-5.8

    all

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-intel-5.13

    all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-kvm

    < 4.4.0-1089.98 | < 4.15.0-1089.91 | < 5.4.0-1034.35

  • ubuntulinux-lts-xenial

    < 4.4.0-204.236~14.04.1

  • ubuntulinux-oem

    all

  • ubuntulinux-oem-5.10

    < 5.10.0-1014.15

  • ubuntulinux-oem-5.6

    all

  • ubuntulinux-oracle

    < 4.15.0-1069.77~16.04.1 | < 4.15.0-1069.77 | < 5.4.0-1039.42

  • ubuntulinux-oracle-5.0

    all

  • ubuntulinux-oracle-5.3

    all

  • ubuntulinux-oracle-5.4

    < 5.4.0-1039.42~18.04.1

  • ubuntulinux-oracle-5.8

    all

  • ubuntulinux-raspi

    < 5.4.0-1030.33

  • ubuntulinux-raspi-5.4

    < 5.4.0-1030.33~18.04.1

Showing first 50 affected entries in server-rendered view.

References (6)