CVE-2021-39735 describes a memory corruption vulnerability in the Android kernel's gasket_alloc_coherent_memory function, specifically within gasket_page_table.c, due to a race condition. This flaw affects Android devices and could enable local escalation of privilege. The vulnerability has a CVSS score of 6.4 (Medium), indicating a local attack vector with high attack complexity, requiring high privileges for exploitation, but no user interaction. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.