In authToken2AidlVec of KeyMintUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-242702451
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/pixel/2022-12-01 | Patch Vendor Advisory |
Configurations
Information
Published : 2022-12-16 08:15
Updated : 2022-12-20 13:20
NVD link : CVE-2022-20549
Mitre link : CVE-2022-20549
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
- android