Vulnerability record · CVE-2021-39793 · published 16 March 2022
CVE-2021-39793: Android Mali GPU driver out-of-bounds write in kbase_jd_user_buf_pin_pages
Google · Android
The Android kernel Mali GPU driver function kbase_jd_user_buf_pin_pages in mali_kbase_mem.c contains a logic error that causes an out-of-bounds write. A local attacker can trigger the flaw to corrupt memory and escalate privileges. It matters because the bug is in a core kernel driver and CISA lists it as exploited in the wild.
Description
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with local privilege escalation and confirmed CISA KEV exploitation, though EPSS is low and no ransomware link is documented.
What it is
The Android kernel Mali GPU driver function kbase_jd_user_buf_pin_pages in mali_kbase_mem.c contains a logic error that causes an out-of-bounds write. A local attacker can trigger the flaw to corrupt memory and escalate privileges. It matters because the bug is in a core kernel driver and CISA lists it as exploited in the wild.
Impact
An attacker gains local privilege escalation, potentially reaching kernel-level code execution on the affected device. No additional execution privileges are required beyond local access.
Attack surface
The flaw is reached locally through the Mali GPU driver interface, requiring low privileges (PR:L) and no user interaction (UI:N). No remote or network vector is described.
Exploitation
CVE-2021-39793 is listed in CISA KEV with a 2022-04-11 addition date, indicating known exploitation, while EPSS is low at 0.00738 (52.8th percentile). No ransomware campaign use is documented.
What to do
- Apply the Android Pixel security bulletin updates for 2022-03-01 or later vendor patches.
- Restrict local access and untrusted app installation on affected Android devices.
- Monitor for and remove sideloaded or malicious apps that could invoke the GPU driver.
- Track vendor kernel updates for Mali driver fixes and deploy promptly.
Detection
- Monitor kernel logs for Mali kbase driver errors or crashes tied to kbase_jd_user_buf_pin_pages.
- Watch for unexpected privilege escalation or anomalous processes gaining root on Android devices.
- Audit installed apps for untrusted sources that could exercise GPU memory pinning paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-39793 to the Known Exploited Vulnerabilities catalog on 11 April 2022 as "Google Pixel Out-of-Bounds Write Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 2 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://source.android.com/security/bulletin/pixel/2022-03-01 | Vendor Advisory |
| https://source.android.com/security/bulletin/pixel/2022-03-01 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-39793 | Third Party AdvisoryUS Government Resource |
Track CVE-2021-39793 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-39793), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.