CVE-2022-41577Out-of-bounds Read in Huawei Emui

CWE-125Out-of-bounds Read3 documents3 sources
Severity
7.1HIGHNVD
EPSS
0.0%
top 93.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 14

Description

The kernel server has a vulnerability of not verifying the length of the data transferred in the user space.Successful exploitation of this vulnerability may cause out-of-bounds read in the kernel, which affects the device confidentiality and availability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages4 packages

CVEListV5huawei/emui12.0.0
NVDhuawei/emui12.0.0
CVEListV5huawei/harmonyos2.0, 2.1+1
NVDhuawei/harmonyos2.0, 2.1+1

🔴Vulnerability Details

2
GHSA
GHSA-4r2p-352m-7q6g: The kernel server has a vulnerability of not verifying the length of the data transferred in the user space2022-10-14
CVEList
CVE-2022-41577: The kernel server has a vulnerability of not verifying the length of the data transferred in the user space2022-10-14
CVE-2022-41577 — Out-of-bounds Read in Huawei Emui | cvebase