CVE-2021-39713
Aliases:UBUNTU-CVE-2021-39713DEBIAN-CVE-2021-39713
Advisory lineage Upstream: 0 Downstream: 25
Modified
Published: 16 Mar 2022, 14:03
Last modified:04 Aug 2024, 02:13
Vulnerability Summary
Overall Risk (default)
medium
38/100 CVSS Score
7 HIGH
v3.1 (nvd)
EPSS Score
0.21% LOW
0% probability +0.19%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
16 Mar 2022, 14:03
Published
Vulnerability first disclosed
04 Aug 2024, 02:13
Last Modified
Vulnerability information updated
Description
Product: AndroidVersions: Android kernelAndroid ID: A-173788806References: Upstream kernel
CVSS Metrics
- v3.1•HIGH•Score: 7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.9AV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.21%• Percentile: 11%
Techniques & Countermeasures
- CWE-362•Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Affected Systems
- debian•linux
< 5.2.6-1 | < 5.2.6-1 | < 5.2.6-1 | < 5.2.6-1
- ubuntu•linux
< 3.13.0-190.241 | < 4.4.0-224.257
- ubuntu•linux-aws
< 4.4.0-1104.109 | < 4.4.0-1140.154
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-azure
< 4.15.0-1013.13~16.04.2 | all
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.4.0-1074.80 | all
- ubuntu•linux-gcp
< 4.15.0-1014.14~16.04.1 | all
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-hwe
< 4.15.0-24.26~16.04.1 | all
- ubuntu•linux-hwe-5.11
all
- ubuntu•linux-hwe-5.8
all
- ubuntu•linux-hwe-edge
all
- ubuntu•linux-intel-5.13
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1105.114
- ubuntu•linux-lts-xenial
< 4.4.0-224.257~14.04.1
- ubuntu•linux-oem
all
- ubuntu•linux-oem-5.10
all
- ubuntu•linux-oem-5.13
all
- ubuntu•linux-oem-5.6
all
- ubuntu•linux-oracle-5.0
all
- ubuntu•linux-oracle-5.11
all
- ubuntu•linux-oracle-5.3
all
- ubuntu•linux-oracle-5.8
all
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
all
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all
- ubuntu•linux-riscv-5.11
all
- ubuntu•linux-riscv-5.8
all
- ubuntu•linux-snapdragon
< 4.15.0-1053.57
- debian•debian_linux
9.0
- google•android
na
References (14)
- https://source.android.com/security/bulletin/pixel/2022-03-01
- http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html
- https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html
- https://ubuntu.com/security/CVE-2021-39713
- https://android.googlesource.com/kernel/common/+/e368fdb61d8e7
- https://android.googlesource.com/kernel/common/+/9d7e82cec35c0
- https://android.googlesource.com/kernel/common/+/3a7d0d07a3867
- https://android.googlesource.com/kernel/common/+/86bd446b5cebd
- https://android.googlesource.com/kernel/common/+/6f99528e97977
- https://syzkaller.appspot.com/bug?id=d7e411c5472dd5da33d8cc921ccadc747743a568
- https://ubuntu.com/security/notices/USN-5413-1
- https://ubuntu.com/security/notices/USN-5484-1
- https://www.cve.org/CVERecord?id=CVE-2021-39713
- https://security-tracker.debian.org/tracker/CVE-2021-39713