PT-2022-14405 · Google · Android Kernel

Published

2022-06-15

·

Updated

2023-08-08

·

CVE-2022-20176

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android kernel versions (affected versions not specified)
Description In the auth store of sjtag-driver.c, there is a possible read of uninitialized memory due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

CVE-2022-20176

Affected Products

Android Kernel