PT-2020-11433 · Google+2 · Android Kernel+2

Chao Yu

+1

·

Published

2020-04-17

·

Updated

2022-07-30

·

CVE-2020-0067

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to a missing bounds check in the f2fs xattr generic list function of xattr.c, which could lead to a possible out of bounds read. This may result in local information disclosure, requiring System execution privileges for exploitation. No user interaction is needed for exploitation.
Recommendations For Android kernel, consider applying a patch that includes a bounds check for the f2fs xattr generic list function to prevent out of bounds reads. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-0067
LSN-0072-1
USN-4387-1
USN-4388-1
USN-4389-1
USN-4390-1
USN-4527-1

Affected Products

Android Kernel
Linuxmint
Ubuntu