PT-2022-4763 · Google · Android Kernel

Published

2022-06-06

·

Updated

2025-02-11

·

CVE-2022-20186

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to improper input validation in the kbase mem alias function of mali kbase mem linux.c, which could lead to arbitrary code execution and local escalation of privilege without requiring additional execution privileges. User interaction is not needed for exploitation. The vulnerability allows mapping arbitrary physical pages to the GPU memory with both read and write access, enabling arbitrary kernel code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-05663
CVE-2022-20186

Affected Products

Android Kernel