In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210292376References: Upstream kernel
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2940-1 | linux security update |
Debian DLA |
DLA-2941-1 | linux-4.19 security update |
Debian DSA |
DSA-5050-1 | linux security update |
Debian DSA |
DSA-5096-1 | linux security update |
EUVD |
EUVD-2021-26042 | In various setup methods of the USB gadget subsystem, there is a possible out of bounds write due to an incorrect flag check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210292376References: Upstream kernel |
Ubuntu USN |
USN-5278-1 | Linux kernel (OEM) vulnerabilities |
Ubuntu USN |
USN-5294-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5294-2 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5297-1 | Linux kernel (GKE) vulnerabilities |
Ubuntu USN |
USN-5298-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5337-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5368-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5505-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-5513-1 | Linux kernel (AWS) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2024-08-04T02:13:37.681Z
Reserved: 2021-08-23T00:00:00
Link: CVE-2021-39685
No data.
Status : Modified
Published: 2022-03-16T15:15:10.377
Modified: 2024-11-21T06:20:00.253
Link: CVE-2021-39685
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN