PT-2022-14364 · Imagination Technologies+1 · Powervr-Gpu+1

Published

2022-08-24

·

Updated

2022-08-29

·

CVE-2022-20122

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android SoC versions (affected versions not specified)
Description The PowerVR GPU driver has an issue where unprivileged apps can allocate pinned memory, unpin it, and continue using the page in GPU calls without requiring any privileges. This results in kernel memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-20122

Affected Products

Android
Powervr-Gpu