CVE-2022-20412Out-of-bounds Read in Google Android

CWE-125Out-of-bounds Read4 documents4 sources
Severity
6.7MEDIUMNVD
EPSS
0.0%
top 96.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateOct 12

Description

In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-230794395

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages4 packages

CVEListV5google/androidAndroid-10 Android-11 Android-12 Android-12L Android-13
NVDgoogle/android5 versions+4
Androidplatform/external_dtc10:010:2022-10-01+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mm67-rq52-jpj4: In fdt_next_tag of fdt2022-10-12
OSV
CVE-2022-20412: In fdt_next_tag of fdt2022-10-01

📋Vendor Advisories

1
Android
CVE-2022-20412: Android Security Bulletin 2022-10-01 CVE: CVE-2022-20412 Severity: HIGH Type: EoP Affected AOSP versions: 10, 11, 12, 12L, 13 References: A-2307943952022-10-01