PT-2024-24953 · Google · Android

Published

2024-06-13

·

Updated

2024-08-19

·

CVE-2024-32900

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android versions prior to the fixed version
Description The issue is related to a possible Use after Free due to improper locking in the lwis fence signal function of lwis debug.c. This could lead to local escalation of privilege from the hal camera default SELinux label with no additional execution privileges needed. User interaction is not needed for exploitation.
Recommendations For Android versions prior to the fixed version, consider applying a patch that fixes the improper locking issue in the lwis fence signal function as a permanent solution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-32900

Affected Products

Android