cbcvebase.
CVE-2023-40082
published 2023-12-04

CVE-2023-40082: In modify_for_next_stage of fdt.rs, there is a possible way to render KASLR ineffective due to improperly used crypto. This could lead to remote escalation of…

PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.64%
46.9th percentile
In modify_for_next_stage of fdt.rs, there is a possible way to render KASLR ineffective due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected

5 ranges
VendorProductVersion rangeFixed in
googleandroid
googleandroid
googleandroid
platformpackages_modules_virtualization>= 14-next:0 < 14-next:2023-12-0114-next:2023-12-01
platformpackages_modules_virtualization>= 14:0 < 14:2023-12-0114:2023-12-01

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is located in the `modify_for_next_stage` function within `fdt.rs` — monitor for anomalous modifications to the Flattened Device Tree (FDT) during boot stage transitions on Android 14 devices
  • The exploit renders KASLR ineffective — detection should focus on unexpected kernel base address predictability or KASLR bypass indicators on Android 14 systems
  • No user interaction required and no additional execution privileges needed — exploitation can occur remotely without any local preconditions; treat any unauthenticated remote EoP attempts on Android 14 as high priority
  • Scope is limited to Android 14 (AOSP); prioritize patching and detection on devices running AOSP version 14, tracked under Android internal reference A-290909089
  • ·Only Android 14 (AOSP) is listed as affected; other AOSP versions are not confirmed vulnerable per the bulletin
  • ·The vulnerability involves improper cryptographic usage in the FDT boot stage transition, not a missing crypto primitive — detection/patching must address the specific misuse in modify_for_next_stage rather than simply adding encryption
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.