CVE-2022-20554
published 2022-12-16CVE-2022-20554: In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.17%
7.0th percentile
In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245770596
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| platform | frameworks_native | >= 13:0 < 13:2022-12-01 | 13:2022-12-01 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android 13.0 InputDevice.cpp removeEventHubDevice use after free (A-245770596 / EUVD-2022-25814)
vuldb·2026-04-21·CVSS 6.7
CVE-2022-20554 [MEDIUM] Google Android 13.0 InputDevice.cpp removeEventHubDevice use after free (A-245770596 / EUVD-2022-25814)
A vulnerability was found in Google Android 13.0. It has been classified as problematic. The affected element is the function removeEventHubDevice of the file InputDevice.cpp. Performing a manipulation results in use after free.
This vulnerability was named CVE-2022-20554. The attack needs to be approached locally. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.
GHSA
GHSA-4phr-7mh9-vvgh: In removeEventHubDevice of InputDevice
ghsa_unreviewed·2022-12-20
CVE-2022-20554 [MEDIUM] CWE-416 GHSA-4phr-7mh9-vvgh: In removeEventHubDevice of InputDevice
In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245770596
OSV
CVE-2022-20554: In removeEventHubDevice of InputDevice
osv·2022-12-01
CVE-2022-20554 CVE-2022-20554: In removeEventHubDevice of InputDevice
In removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-16
Published