CVE-2022-0247: Write access to VMO data through copy-on-write in Fuchsia
Published Feb 25, 2022
·Updated
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.
Affected Software
1 affected component
Google Fuchsia<2022-01-03
Remediation
Event History
Feb 25, 2022
CVE Published
via MITRE·11:10 AM
Data Sourced
via MITRE·11:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-0247.
2
What is the severity level of CVE-2022-0247?
CVE-2022-0247 has a severity level of high.
3
What is the affected software?
The affected software is Google Fuchsia.
4
How can an attacker exploit CVE-2022-0247?
A local attacker can exploit CVE-2022-0247 by modifying objects in the VMO that they do not have permission to.
5
How can I fix CVE-2022-0247?
To fix CVE-2022-0247, we recommend upgrading to a version past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.