CVE-2022-20228
published 2022-07-13CVE-2022-20228: In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free. This could lead to remote information disclosure…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.56%
42.6th percentile
In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213850092
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_av | >= 12:0 < 12:2022-07-01 | 12:2022-07-01 |
| platform | frameworks_av | >= 12L:0 < 12L:2022-07-01 | 12L:2022-07-01 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2022-20228: Android Security Bulletin 2022-07-01
CVE: CVE-2022-20228
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L
References: A-213850092
vendor_android·2022-07-01·CVSS 6.5
CVE-2022-20228 [MEDIUM] CVE-2022-20228: Android Security Bulletin 2022-07-01
CVE: CVE-2022-20228
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L
References: A-213850092
Android Security Bulletin 2022-07-01
CVE: CVE-2022-20228
Severity: HIGH
Type: ID
Affected AOSP versions: 12, 12L
References: A-213850092
GHSA
GHSA-jjqr-rxfx-r766: In various functions of C2DmaBufAllocator
ghsa_unreviewed·2022-07-14
CVE-2022-20228 [MEDIUM] CWE-416 GHSA-jjqr-rxfx-r766: In various functions of C2DmaBufAllocator
In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-213850092
OSV
CVE-2022-20228: In various functions of C2DmaBufAllocator
osv·2022-07-01
CVE-2022-20228 CVE-2022-20228: In various functions of C2DmaBufAllocator
In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-13
Published