PT-2022-11073 · Google · Android
Published
2022-04-01
·
Updated
2022-04-18
·
CVE-2021-39798
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android versions Android-12 through Android-12L
Description
The issue is related to a missing bounds check in the Bitmap createFromParcel function of Bitmap.cpp, which could lead to arbitrary code execution. This might result in local escalation of privilege, requiring User execution privileges. No user interaction is needed for exploitation.
Recommendations
For Android versions Android-12 through Android-12L, consider restricting access to the
Bitmap createFromParcel function until a patch is available. As a temporary workaround, avoid using the Bitmap createFromParcel function to minimize the risk of exploitation.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android