CVE-2022-20412
published 2022-10-11CVE-2022-20412: In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.14%
3.4th percentile
In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-230794395
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | external_dtc | >= 10:0 < 10:2022-10-01 | 10:2022-10-01 |
| platform | external_dtc | >= 11:0 < 11:2022-10-01 | 11:2022-10-01 |
| platform | external_dtc | >= 12:0 < 12:2022-10-01 | 12:2022-10-01 |
| platform | external_dtc | >= 12L:0 < 12L:2022-10-01 | 12L:2022-10-01 |
| platform | external_dtc | >= 13:0 < 13:2022-10-01 | 13:2022-10-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mm67-rq52-jpj4: In fdt_next_tag of fdt
ghsa_unreviewed·2022-10-12
CVE-2022-20412 [MEDIUM] CWE-125 GHSA-mm67-rq52-jpj4: In fdt_next_tag of fdt
In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-230794395
OSV
CVE-2022-20412: In fdt_next_tag of fdt
osv·2022-10-01
CVE-2022-20412 CVE-2022-20412: In fdt_next_tag of fdt
In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2022-20412: Android Security Bulletin 2022-10-01
CVE: CVE-2022-20412
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-230794395
vendor_android·2022-10-01·CVSS 6.7
CVE-2022-20412 [MEDIUM] CVE-2022-20412: Android Security Bulletin 2022-10-01
CVE: CVE-2022-20412
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-230794395
Android Security Bulletin 2022-10-01
CVE: CVE-2022-20412
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-230794395
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published