PT-2022-26475 · Google · Android Kernel

Published

2022-12-16

·

Updated

2022-12-21

·

CVE-2022-42514

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android kernel
Description In the ProtocolImsBuilder::BuildSetConfig function of protocolimsbuilder.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2022-42514

Affected Products

Android Kernel