Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-20385

Опубликовано: 13 сент. 2022
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android SoCAndroid ID: A-238379819

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00192
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1284

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android SoCAndroid ID: A-238379819

CVSS3: 9.8
github
больше 3 лет назад

a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android SoCAndroid ID: A-238379819

EPSS

Процентиль: 41%
0.00192
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1284