PT-2022-14815 · Google · Android Kernel
Published
2022-12-16
·
Updated
2022-12-21
·
CVE-2022-20607
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android kernel
Description
The issue is related to a missing bounds check in the Pixel cellular firmware, which could lead to an out of bounds write. This might result in remote code execution, with LTE authentication required for exploitation. No user interaction is needed for this issue to be exploited.
Recommendations
For Android kernel, apply the necessary patch or update to fix the missing bounds check issue.
As a temporary workaround, consider restricting access to the LTE authentication mechanism until a patch is available.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Kernel