CVE-2022-20514
published 2022-12-16CVE-2022-20514: In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possible out of bounds…
PriorityP430medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.17%
7.0th percentile
In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245727875
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 13.0 Idmap2Service.cpp out-of-bounds write (A-245727875 / EUVD-2022-25774)
vuldb·2026-04-20·CVSS 6.7
CVE-2022-20514 [MEDIUM] Google Android 13.0 Idmap2Service.cpp out-of-bounds write (A-245727875 / EUVD-2022-25774)
A vulnerability, which was classified as critical, has been found in Google Android 13.0. Affected is the function acquireFabricatedOverlayIterator/nextFabricatedOverlayInfos/releaseFabricatedOverlayIterator of the file Idmap2Service.cpp. Performing a manipulation results in out-of-bounds write.
This vulnerability is known as CVE-2022-20514. Attacking locally is a requirement. No exploit is available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-r343-hgp8-8hq5: In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service
ghsa_unreviewed·2022-12-20
CVE-2022-20514 [MEDIUM] CWE-416 GHSA-r343-hgp8-8hq5: In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service
In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245727875
OSV
CVE-2022-20514: In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service
osv·2022-12-01
CVE-2022-20514 CVE-2022-20514: In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service
In acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-16
Published