Описание
dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could lead to an invalid access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
Ссылки
- PatchThird Party Advisory
- PatchVendor Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00088
Низкий
7.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-1188
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
dcc_curr_list is initialized with a default invalid value that is expected to be programmed by the user through a sysfs node which could lead to an invalid access in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
EPSS
Процентиль: 25%
0.00088
Низкий
7.8 High
CVSS3
9.3 Critical
CVSS2
Дефекты
CWE-1188