CVE-2023-40107Use After Free in Frameworks AV

CWE-416Use After Free5 documents5 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 94.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateFeb 16

Description

In ARTPWriter of ARTPWriter.cpp, there is a possible use after free due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Androidplatform/frameworks_av14-next:014-next:2023-11-01+4
CVEListV5google/android4 versions+3
NVDgoogle/android4 versions+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wf34-wc7h-9ffx: In ARTPWriter of ARTPWriter2024-02-16
CVEList
CVE-2023-40107: In ARTPWriter of ARTPWriter2024-02-15
OSV
CVE-2023-40107: In ARTPWriter of ARTPWriter2023-11-01

📋Vendor Advisories

1
Android
CVE-2023-40107: Android Security Bulletin 2023-11-01 CVE: CVE-2023-40107 Severity: HIGH Type: EoP Affected AOSP versions: 12, 12L, 13, 14 References: A-2872987212023-11-01
CVE-2023-40107 — Use After Free in Frameworks AV | cvebase