CVE-2021-39732 is an integer overflow vulnerability in the Android kernel's lwis_ioctl.c, specifically within the copy_io_entries function, leading to a possible out-of-bounds write. This flaw affects Android products and could allow for local escalation of privilege without requiring user interaction or additional execution privileges. The vulnerability has a CVSSv3 score of 7.8 (High), indicating a low attack complexity and local attack vector, with high impacts on confidentiality, integrity, and availability. Its EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild. Currently, there is no known active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has received no community discussion or media coverage, suggesting a low level of public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.