CVE-2021-39648
In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-160822094References: Upstream kernel
- Affected products
- Android Kernel, Suse, Ubuntu
- Google Android
- All versions
- CVSS 3.1
- 4.1 MEDIUM
- EPSS
- 0.2% (6th percentile)
- Weakness
- CWE-362
- NVD status
- Modified
- Published
- 2021-12-15
CVE-2021-39648 at NVD
No indexed exploits for CVE-2021-39648 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2021-39648 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.