← Vulnerability feed

Vulnerability record · CVE-2021-39793 · published 16 March 2022

CVE-2021-39793: Android Mali GPU driver out-of-bounds write in kbase_jd_user_buf_pin_pages

Google · Android

The Android kernel Mali GPU driver function kbase_jd_user_buf_pin_pages in mali_kbase_mem.c contains a logic error that causes an out-of-bounds write. A local attacker can trigger the flaw to corrupt memory and escalate privileges. It matters because the bug is in a core kernel driver and CISA lists it as exploited in the wild.

7.8 CVSS 3.1 High CISA KEV since 11 Apr 2022 EPSS 0.69% · top 49.3% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 7.2
0.69%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityCVSS 7.8 with local privilege escalation and confirmed CISA KEV exploitation, though EPSS is low and no ransomware link is documented.

What it is

The Android kernel Mali GPU driver function kbase_jd_user_buf_pin_pages in mali_kbase_mem.c contains a logic error that causes an out-of-bounds write. A local attacker can trigger the flaw to corrupt memory and escalate privileges. It matters because the bug is in a core kernel driver and CISA lists it as exploited in the wild.

Impact

An attacker gains local privilege escalation, potentially reaching kernel-level code execution on the affected device. No additional execution privileges are required beyond local access.

Attack surface

The flaw is reached locally through the Mali GPU driver interface, requiring low privileges (PR:L) and no user interaction (UI:N). No remote or network vector is described.

Exploitation

CVE-2021-39793 is listed in CISA KEV with a 2022-04-11 addition date, indicating known exploitation, while EPSS is low at 0.00738 (52.8th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Android Pixel security bulletin updates for 2022-03-01 or later vendor patches.
  • Restrict local access and untrusted app installation on affected Android devices.
  • Monitor for and remove sideloaded or malicious apps that could invoke the GPU driver.
  • Track vendor kernel updates for Mali driver fixes and deploy promptly.

Detection

  • Monitor kernel logs for Mali kbase driver errors or crashes tied to kbase_jd_user_buf_pin_pages.
  • Watch for unexpected privilege escalation or anomalous processes gaining root on Android devices.
  • Audit installed apps for untrusted sources that could exercise GPU memory pinning paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-39793 to the Known Exploited Vulnerabilities catalog on 11 April 2022 as "Google Pixel Out-of-Bounds Write Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 2 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-39793 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-58704Android Cellular Modem improper authorization allows adjacent privilege escalationAndroid's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escala…KEVEPSS 0.59%analysed8.8CVE-2025-48543Android use-after-free allows Chrome sandbox escape to system_serverA use-after-free in multiple Android locations lets an attacker escape the Chrome sandbox and reach the Android system_server process. Because the fl…KEVEPSS 0.54%analysed8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2025-48572Android Framework permissions bypass enables background activity launchMultiple locations in the Android Framework allow activities to be launched from the background because of a permissions bypass, a missing authentica…KEVEPSS 0.26%analysed7.8CVE-2024-32896Android Pixel logic error allows local privilege escalationCVE-2024-32896 is a logic error in Android (CWE-670/CWE-783) that permits a local attacker to bypass intended restrictions and escalate privileges. I…KEVEPSS 3.0%analysed7.8CVE-2024-29748Android Pixel logic error allows local privilege escalationCVE-2024-29748 is a logic error in Android code that permits bypassing a security check, leading to local escalation of privilege. It affects Google …KEVEPSS 0.67%analysed7.8CVE-2023-35674Android WindowState logic error allows background activity launch and privilege escalationA logic error in onCreate of WindowState.java in the Android Framework lets a background activity be launched, enabling local escalation of privilege…KEVEPSS 2.6%analysed7.8CVE-2023-20963Android WorkSource parcel mismatch local privilege escalationCVE-2023-20963 is a parcel mismatch in Android's WorkSource component that allows a local attacker to escalate privileges without additional executio…KEVEPSS 1.5%analysed

Source: NIST National Vulnerability Database (record CVE-2021-39793), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.