CVE-2022-32611
published 2022-11-08CVE-2022-32611: In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.13%
3.3th percentile
In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340373; Issue ID: ALPS07340373.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android isp out-of-bounds write (ALPS07340373 / EUVD-2022-35677)
vuldb·2026-05-31·CVSS 6.7
CVE-2022-32611 [MEDIUM] Google Android isp out-of-bounds write (ALPS07340373 / EUVD-2022-35677)
A vulnerability was found in Google Android. It has been rated as critical. The affected element is an unknown function of the component isp. This manipulation causes out-of-bounds write.
This vulnerability is handled as CVE-2022-32611. It is possible to launch the attack on the local host. There is not any exploit available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-hv7h-jqcv-92v9: In isp, there is a possible out of bounds write due to a missing bounds check
ghsa_unreviewed·2022-11-09
CVE-2022-32611 [MEDIUM] CWE-787 GHSA-hv7h-jqcv-92v9: In isp, there is a possible out of bounds write due to a missing bounds check
In isp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07340373; Issue ID: ALPS07340373.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-08
Published