PT-2020-11809 · Google · Android

Published

2020-12-15

·

Updated

2021-07-21

·

CVE-2020-0474

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions Android-11
Description The issue is related to a possible use-after-free due to a race condition in the HalCamera::requestNewFrame function of HalCamera.cpp. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android version Android-11, consider restricting access to the HalCamera module to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the requestNewFrame function could help mitigate the issue. However, specific guidance on how to resolve the issue for each affected version is not fully provided, so it is crucial to await official patches or updates from the vendor.

Fix

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-0474

Affected Products

Android