{"id":"PUB-A-160822094","details":"In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-160822094","CVE-2021-39648"],"modified":"2026-05-19T16:54:37.272608834Z","published":"2021-12-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2021-12-01"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/64e6bbfff52db4bf6785fab9cffab850b2de6870"}],"affected":[{"package":{"name":":linux_kernel:","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":":0"},{"fixed":":2021-12-05"}]}],"versions":["Kernel"],"ecosystem_specific":{"vanir_signatures":[{"target":{"truncated_path_level":1,"file":"drivers/usb/gadget/configfs.c"},"source":"https://android.googlesource.com/kernel/common/+/64e6bbfff52db4bf6785fab9cffab850b2de6870","deprecated":false,"id":"PUB-A-160822094-b4a48689","digest":{"line_hashes":["79247195589095590568277055161225283220","141414295815732894816063577265325991000","86473914779299051518878460939143540079","19493245227855791870427344486394842495","334520433686633874808459603621294536512"],"threshold":0.9},"signature_version":"v1","signature_type":"Line"},{"digest":{"length":178,"function_hash":"337555850625797397627801719672181788232"},"deprecated":false,"source":"https://android.googlesource.com/kernel/common/+/64e6bbfff52db4bf6785fab9cffab850b2de6870","target":{"function":"gadget_dev_desc_UDC_show","truncated_path_level":1,"file":"drivers/usb/gadget/configfs.c"},"id":"PUB-A-160822094-f2e060a8","signature_version":"v1","signature_type":"Function"}],"fixes":["https://android.googlesource.com/kernel/common/+/64e6bbfff52db4bf6785fab9cffab850b2de6870"],"spl":"2021-12-05","severity":"Moderate","types":["ID"]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-160822094.json"}}],"schema_version":"1.7.5"}