{"schema_version":"1.9.0","id":"PUB-A-202511260","published":"2022-03-01T00:00:00Z","modified":"2026-09-10T15:43:18.983809180Z","aliases":["A-202511260","CVE-2021-41864"],"details":"In prealloc_elems_and_freelist of stackmap.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.","affected":[{"package":{"name":":linux_kernel:","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":":0"},{"fixed":":2022-03-05"}]}],"versions":["Kernel"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/kernel/common/+/30e29a9a2bc6a4888335a6ede968b75cd329657a"],"severity":"Moderate","spl":"2022-03-05","types":["EoP"],"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["138355671117931060601386443469335038030","21078963703448784961734780795509455909","307878453625655919730588976003179522762","90440858909143805989969151470339403945"],"threshold":0.9},"id":"PUB-A-202511260-3ca95fcd","signature_type":"Line","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/30e29a9a2bc6a4888335a6ede968b75cd329657a","target":{"file":"kernel/bpf/stackmap.c"}},{"deprecated":false,"digest":{"function_hash":"78331623464240500637050481890227317480","length":472},"id":"PUB-A-202511260-7e8b55b7","signature_type":"Function","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/30e29a9a2bc6a4888335a6ede968b75cd329657a","target":{"file":"kernel/bpf/stackmap.c","function":"prealloc_elems_and_freelist"}}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/PUB-A-202511260.json"}}],"references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2022-03-01"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/30e29a9a2bc6a4888335a6ede968b75cd329657a"}]}