PT-2020-11809 · Google · Android
Published
2020-12-15
·
Updated
2021-07-21
·
CVE-2020-0474
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions Android-11
Description
The issue is related to a possible use-after-free due to a race condition in the
HalCamera::requestNewFrame function of HalCamera.cpp. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Recommendations
For Android version Android-11, consider restricting access to the
HalCamera module to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the requestNewFrame function could help mitigate the issue. However, specific guidance on how to resolve the issue for each affected version is not fully provided, so it is crucial to await official patches or updates from the vendor.Fix
Race Condition
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android