PT-2022-2177 · Google · Android

CVE-2021-39708

·

Published

2022-03-01

·

Updated

2023-08-08

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-12
Description The issue is related to a function gatt process notification in gatt cl.cc of the Android operating system kernel, which is associated with inadequate access control. This could allow a remote attacker to escalate their privileges due to an incorrect bounds check, potentially leading to an out-of-bounds write. No additional execution privileges are needed, and user interaction is not required for exploitation.
Recommendations For Android version Android-12, consider restricting access to the gatt process notification function in gatt cl.cc until a patch is available. As a temporary workaround, disabling the gatt process notification function may help minimize the risk of exploitation.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-206128341
BDU:2022-02188
CVE-2021-39708

Affected Products

Android