PT-2022-10969 · Google · Android Kernel

Published

2022-01-14

·

Updated

2022-07-12

·

CVE-2021-39684

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is caused by a logic error in the code, leading to a possible allocation of RWX memory in the target init function of gs101/abl/target/slider/target.c. This could result in local escalation of privilege with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations For Android kernel, consider applying a patch to fix the logic error in the target init function as a permanent solution. As a temporary workaround, restrict access to the target init function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-39684

Affected Products

Android Kernel