CVE-2022-20454
published 2022-11-08CVE-2022-20454: In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System…
PriorityP429medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.13%
3.2th percentile
In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242096164
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | external_dtc | >= 10:0 < 10:2022-11-01 | 10:2022-11-01 |
| platform | external_dtc | >= 11:0 < 11:2022-11-01 | 11:2022-11-01 |
| platform | external_dtc | >= 12:0 < 12:2022-11-01 | 12:2022-11-01 |
| platform | external_dtc | >= 12L:0 < 12L:2022-11-01 | 12L:2022-11-01 |
| platform | external_dtc | >= 13:0 < 13:2022-11-01 | 13:2022-11-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 10.0/11.0/12.0/13.0 fdt.c fdt_next_tag out-of-bounds write (A-242096164 / EUVD-2022-25714)
vuldb·2026-04-15·CVSS 6.7
CVE-2022-20454 [MEDIUM] Google Android 10.0/11.0/12.0/13.0 fdt.c fdt_next_tag out-of-bounds write (A-242096164 / EUVD-2022-25714)
A vulnerability labeled as critical has been found in Google Android 10.0/11.0/12.0/13.0. The affected element is the function fdt_next_tag of the file fdt.c. Such manipulation leads to out-of-bounds write.
This vulnerability is referenced as CVE-2022-20454. The attack can only be performed from a local environment. No exploit is available.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-72gj-xg53-728v: In fdt_next_tag of fdt
ghsa_unreviewed·2022-11-09
CVE-2022-20454 [MEDIUM] CWE-190 GHSA-72gj-xg53-728v: In fdt_next_tag of fdt
In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242096164
OSV
CVE-2022-20454: In fdt_next_tag of fdt
osv·2022-11-01
CVE-2022-20454 CVE-2022-20454: In fdt_next_tag of fdt
In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Android
CVE-2022-20454: Android Security Bulletin 2022-11-01
CVE: CVE-2022-20454
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-242096164
vendor_android·2022-11-01·CVSS 6.7
CVE-2022-20454 [MEDIUM] CVE-2022-20454: Android Security Bulletin 2022-11-01
CVE: CVE-2022-20454
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-242096164
Android Security Bulletin 2022-11-01
CVE: CVE-2022-20454
Severity: HIGH
Type: EoP
Affected AOSP versions: 10, 11, 12, 12L, 13
References: A-242096164
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-08
Published