CVE-2021-39685
Vulnerability Summary
Timeline
Description
In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210292376References: Upstream kernel
CVSS Metrics
- v4.0•MEDIUM•Score: 5.4CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.46%• Percentile: 39%
Techniques & Countermeasures
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- debian•linux
< 5.10.92-1 | < 5.15.5-2 | < 5.15.5-2 | < 5.15.5-2
- ubuntu•linux
all | < 4.4.0-229.263 | < 4.15.0-169.177 | < 5.4.0-100.113
- ubuntu•linux-aws
< 4.4.0-1109.115 | < 4.4.0-1145.160 | < 4.15.0-1121.129 | < 5.4.0-1066.69
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
< 5.13.0-1019.21~20.04.1
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1066.69~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-fips
< 4.15.0-2061.63 | all | < 5.4.0-1069.73+fips2
- ubuntu•linux-aws-hwe
< 4.15.0-1120.128~16.04.1
- ubuntu•linux-azure
< 4.15.0-1131.144~14.04.1 | < 4.15.0-1131.144~16.04.1 | all | < 5.4.0-1070.73
- ubuntu•linux-azure-4.15
< 4.15.0-1131.144
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
< 5.13.0-1021.24~20.04.1
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1070.73~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fips
< 4.15.0-2043.47 | all | < 5.4.0-1073.76+fips1
- ubuntu•linux-bluefield
all | < 5.4.0-1028.31
- ubuntu•linux-dell300x
< 4.15.0-1035.40
- ubuntu•linux-fips
< 4.4.0-1079.86 | all | < 4.15.0-1078.87 | < 5.4.0-1043.49
- ubuntu•linux-gcp
< 4.15.0-1116.130~16.04.1 | all | < 5.4.0-1065.69
- ubuntu•linux-gcp-4.15
< 4.15.0-1116.130
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
< 5.13.0-1021.25~20.04.1
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1065.69~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-fips
< 4.15.0-2026.28 | all | < 5.4.0-1067.71~20.04.1
- ubuntu•linux-gke
< 5.4.0-1063.66
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.4
< 5.4.0-1063.66~18.04.1
- ubuntu•linux-gkeop
< 5.4.0-1034.35
- ubuntu•linux-gkeop-5.4
< 5.4.0-1034.35~18.04.1
- ubuntu•linux-hwe
< 4.15.0-169.177~16.04.1 | all
- ubuntu•linux-hwe-5.11
all
- ubuntu•linux-hwe-5.13
< 5.13.0-37.42~20.04.1
- ubuntu•linux-hwe-5.4
< 5.4.0-100.113~18.04.1
- ubuntu•linux-hwe-5.8
all
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-ibm
< 5.4.0-1015.16
- ubuntu•linux-ibm-5.4
< 5.4.0-1015.16~18.04.1
- ubuntu•linux-intel-5.13
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1110.120 | < 4.15.0-1107.109 | < 5.4.0-1056.58
- ubuntu•linux-lts-xenial
< 4.4.0-229.263~14.04.1
- ubuntu•linux-oem
all
- ubuntu•linux-oem-5.10
all
Showing first 50 affected entries in server-rendered view.
References (15)
- https://source.android.com/security/bulletin/2022-03-01
- https://ubuntu.com/security/CVE-2021-39685
- https://www.openwall.com/lists/oss-security/2021/12/15/4
- https://github.com/szymonh/inspector-gadget
- https://ubuntu.com/security/notices/USN-5278-1
- https://ubuntu.com/security/notices/USN-5294-1
- https://ubuntu.com/security/notices/USN-5294-2
- https://ubuntu.com/security/notices/USN-5297-1
- https://ubuntu.com/security/notices/USN-5298-1
- https://ubuntu.com/security/notices/USN-5337-1
- https://ubuntu.com/security/notices/USN-5368-1
- https://ubuntu.com/security/notices/USN-5505-1
- https://ubuntu.com/security/notices/USN-5513-1
- https://www.cve.org/CVERecord?id=CVE-2021-39685
- https://security-tracker.debian.org/tracker/CVE-2021-39685