CVE-2021-39793
KEVmassOut-of-Bounds Write in Google Pixel Kernel Driver Enables Local Privilege Escalation
CISA: Google Pixel Out-of-Bounds Write Vulnerability
CVE-2021-39793 is an out-of-bounds write (CWE-787) in the kbase_jd_user_buf_pin_pages function of mali_kbase_mem.c — the Mali GPU kernel driver used in Google Pixel devices — caused by a logic error in the code. A local application or process can trigger the flaw via the GPU driver's user-buffer pinning routine without needing any additional execution privileges or user interaction. Successful exploitation lets the attacker write out of bounds in kernel memory and achieve local escalation of privilege, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). All Google Pixel devices running affected Android kernel builds are affected; the CISA record lists Google/Android as the vendor/product and designates Google Pixel as the affected product. The bug is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-04-11, no public proof-of-concept is known, and EPSS estimates a 0.7% probability of exploitation within 30 days.
What to do: Apply Google's Android security updates on every Pixel device, per CISA's required action to apply updates per vendor instructions; patches were available as of the April 2022 KEV addition, so ensure devices are on an April 2022 or later security patch level (verify in Settings > About phone > Android security update). There is no known workaround, and because exploitation requires local code execution, review apps installed on unpatched devices and prioritize fleet-wide patching for enterprise-managed Pixel fleets.
| Google Android (kernel; Mali GPU driver, mali_kbase_mem.c) on Google Pixel devices | Android kernel builds on Pixel devices; the source data does not specify affected version ranges — fixed via Google/Android security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A
- Affected
- Google Pixel
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Products
- android
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H