CVE-2021-39804: Null Pointer Dereference
In reinit of HeifDecoderImpl.cpp, there is a possible crash due to a missing null check. This could lead to remote persistent denial of service in the file picker with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12LAndroid ID: A-215002587
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39804?
CVE-2021-39804 has been classified as a medium severity vulnerability due to its potential for remote persistent denial of service.
How do I fix CVE-2021-39804?
To fix CVE-2021-39804, ensure that you update your Android device to the latest version released by Google that addresses this vulnerability.
What versions of Android are affected by CVE-2021-39804?
CVE-2021-39804 affects Android versions 11.0, 12.0, and 12.1.
What type of attack does CVE-2021-39804 enable?
CVE-2021-39804 enables a possible crash that can lead to remote persistent denial of service through user interaction.
Is user interaction required for exploiting CVE-2021-39804?
Yes, user interaction is required to exploit the vulnerability identified as CVE-2021-39804.