VDB

CVE-2021-39632

CVE-2021-39632 PUBLISHED CVSS 7.800000190734863 HIGH

In inotify_cb of events.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-202159709

EPSS 0.01% · 2.0th percentile

Risk Scores

CVSS v3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.01%
2.0th percentile

Affected Products

VendorProductVersions
n/aAndroidAndroid-11 Android-12
googleandroid11.0, 12.0

Timeline

  • Jan 5, 2022 CVE Published
  • Jan 15, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 9, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jun 24, 2022 EPSS Score
  • Aug 17, 2022 EPSS Score
  • Oct 9, 2022 EPSS Score
  • Dec 1, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 18, 2023 EPSS Score
  • May 10, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›