CVE-2022-20008

CVSS v3.1 4.6 (Medium)
46% Progress
CVSS v2.0 2.1 (Low)
21% Progress
EPSS 0.04 % (17th)
0.04% Progress
Affected Products 1
Advisories 13

In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216481035References: Upstream kernel

Weaknesses
CWE-908
Use of Uninitialized Resource
CVE Status
PUBLISHED
CNA
Android (associated with Google Inc. or Open Handset Alliance)
Published Date
2022-05-10 20:15:09
(2 years ago)
Updated Date
2022-05-16 16:04:29
(2 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Google Android cpe:2.3:o:google:android:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...