Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-39657
HistoryDec 15, 2021 - 12:00 a.m.

CVE-2021-39657

2021-12-1500:00:00
ubuntu.com
ubuntu.com
23
ufshcd_eh_device_reset_handler
out of bounds read
information disclosure
android kernel
system execution privileges

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

5.1%

In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of
bounds read due to a missing bounds check. This could lead to local
information disclosure with System execution privileges needed. User
interaction is not needed for exploitation.Product: AndroidVersions:
Android kernelAndroid ID: A-194696049References: Upstream kernel

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchlinux< 4.15.0-141.145UNKNOWN
ubuntu20.04noarchlinux< 5.4.0-67.75UNKNOWN
ubuntu16.04noarchlinux< 4.4.0-204.236UNKNOWN
ubuntu18.04noarchlinux-aws< 4.15.0-1098.105UNKNOWN
ubuntu20.04noarchlinux-aws< 5.4.0-1039.41UNKNOWN
ubuntu14.04noarchlinux-aws< 4.4.0-1087.91UNKNOWN
ubuntu16.04noarchlinux-aws< 4.4.0-1123.137UNKNOWN
ubuntu18.04noarchlinux-aws-5.4< 5.4.0-1039.41~18.04.1UNKNOWN
ubuntu16.04noarchlinux-aws-hwe< 4.15.0-1098.105~16.04.1UNKNOWN
ubuntu20.04noarchlinux-azure< 5.4.0-1041.43UNKNOWN
Rows per page:
1-10 of 401

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

5.1%