CVE-2022-20235Out-of-bounds Write in Google Android

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 87.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 26

Description

The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem. This page can only be written by the GPU driver itself, but prior to DDK 1.18 however, a user-space program could write arbitrary data to the page, leading to memory corruption issues.Product: AndroidVersions: Android SoCAndroid ID: A-259967780

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-c474-93fq-8fxp: The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem2023-01-26
OSV
CVE-2022-20235: The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem2023-01-01

📋Vendor Advisories

1
Android
CVE-2022-20235: PowerVR-GPU2023-01-01