Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4h3-hq3r-rqx8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel

In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel

EPSS

Процентиль: 8%
0.00032
Низкий

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel

CVSS3: 7.8
redhat
около 4 лет назад

In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel

CVSS3: 7.8
nvd
почти 4 года назад

In __hidinput_change_resolution_multipliers of hid-input.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-173843328References: Upstream kernel

CVSS3: 7.8
debian
почти 4 года назад

In __hidinput_change_resolution_multipliers of hid-input.c, there is a ...

suse-cvrf
почти 4 года назад

Security update for the Linux Kernel (Live Patch 25 for SLE 15 SP1)

EPSS

Процентиль: 8%
0.00032
Низкий

Дефекты

CWE-787