CVE-2021-39809: High severity Google Android vulnerability
Published Apr 4, 2022
·Updated
In avrcctrlparsvendorrsp of avrcparsct.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205837191
Affected Software
5 affected components
Google Android=10.0
Google Android=11.0
Google Android=12.0
Google Android=12.1
Google Android
Remediation
Patch Available
Event History
Apr 4, 2022
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Apr 12, 2022
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Android releases are affected?
The affected releases listed are Android 10, Android 11, Android 12, and Android 12L.
2
What access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable with no privileges and no user interaction required. Successful exploitation may disclose information.
3
Is a fix available?
Yes. A patch is available, with the referenced Android security bulletin dated 2022-04-01.