CVE-2023-40082Packages Modules Virtualization vulnerability

5 documents5 sources
Severity
9.8CRITICALNVD
EPSS
2.0%
top 16.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 4
Latest updateDec 5

Description

In modify_for_next_stage of fdt.rs, there is a possible way to render KASLR ineffective due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

Androidplatform/packages_modules_virtualization14-next:014-next:2023-12-01+1
CVEListV5google/android14
NVDgoogle/android14.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fc33-wf68-wr6h: In modify_for_next_stage of fdt2023-12-05
CVEList
CVE-2023-40082: In modify_for_next_stage of fdt2023-12-04
OSV
CVE-2023-40082: In modify_for_next_stage of fdt2023-12-01

📋Vendor Advisories

1
Android
CVE-2023-40082: Android Security Bulletin 2023-12-01 CVE: CVE-2023-40082 Severity: HIGH Type: EoP Affected AOSP versions: 14 References: A-2909090892023-12-01
CVE-2023-40082 — CRITICAL severity | cvebase