In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A
Conclusion & alert: CVE-2021-39793 is rated Active Exploitation (74/100): CVSS High severity, with low exploitation likelihood (EPSS 0.73%).Core evidence: CISA KEV confirms active exploitation (added 2022-04-11) affecting Google / Pixel. a weakness (CWE-787) Unauthenticated remote administrative access may be possible.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
CISA KEV Record for CVE-2021-39793
Name: Google Pixel Out-of-Bounds Write Vulnerability · CISA KEV detail
Exploit added: 2022-04-11
Action due: 2022-05-02
Required action: Apply updates per vendor instructions.
Exploit prediction scoring system (EPSS) score for CVE-2021-39793
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).