CVE-2021-39732

HIGH

Android - Integer Overflow to Out-of-Bounds Write in lwis_ioctl.c copy_io_entries

Title source: llm
STIX 2.1

Description

In copy_io_entries of lwis_ioctl.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-205992503References: N/A

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 1.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190 CWE-787
Status published
Products (1)
google/android
Published Mar 16, 2022
Tracked Since Feb 18, 2026