PT-2022-2920 · Google · Fuchsia

Published

2022-03-02

·

Updated

2023-07-21

·

CVE-2022-0882

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fuchsia versions prior to 4.1.1
Description The issue is related to information disclosure. An attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX RSRC KIND ROOT.
Recommendations For versions prior to 4.1.1, upgrade the Fuchsia kernel to 4.1.1 or greater. As a temporary workaround, consider restricting access to the Zircon kernel addresses to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2022-03521
CVE-2022-0882

Affected Products

Fuchsia