CVE-2022-0882: Illegal access to Kernel log in Fuchsia
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZXRSRCKINDROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0882?
CVE-2022-0882 is a vulnerability in the Fuchsia kernel where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT.
How severe is CVE-2022-0882?
CVE-2022-0882 has a severity score of 5.5, which is considered medium.
What software is affected by CVE-2022-0882?
Google Fuchsia versions up to and excluding 4.1.1 are affected by CVE-2022-0882.
How can I fix CVE-2022-0882?
To fix CVE-2022-0882, it is recommended to upgrade the Fuchsia kernel to version 4.1.1 or greater.
Where can I find more information about CVE-2022-0882?
You can find more information about CVE-2022-0882 at the following link: https://bugs.fuchsia.dev/p/fuchsia/issues/detail?id=94740