PT-2022-6531 · Google+4 · Android Kernel+4

Published

2022-11-08

·

Updated

2023-08-08

·

CVE-2022-20572

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to a missing permission check in the verity target of dm-verity-target.c, which could allow modification of read-only files. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android kernel, consider applying a patch from the upstream kernel to fix the missing permission check in the verity target of dm-verity-target.c. As a temporary workaround, consider restricting access to the verity target function until a patch is available.

Fix

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02113
CESA-2022_7444
CESA-2022_7683
CVE-2022-20572
OESA-2022-2160
OESA-2022-2161
OESA-2022-2162
RHSA-2022:7444
RHSA-2022:7683
RHSA-2022:7933
RHSA-2022:8267
RHSA-2022_7444
RHSA-2022_7683
RHSA-2022_7933
RHSA-2022_8267
USN-6001-1
USN-6013-1
USN-6014-1

Affected Products

Android Kernel
Astra Linux
Centos
Red Hat
Ubuntu