First published: Tue May 03 2022(Updated: )
A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater.
Credit: cve-coordination@google.com cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Fuchsia | <4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0882 is a vulnerability in the Fuchsia kernel where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT.
CVE-2022-0882 has a severity score of 5.5, which is considered medium.
Google Fuchsia versions up to and excluding 4.1.1 are affected by CVE-2022-0882.
To fix CVE-2022-0882, it is recommended to upgrade the Fuchsia kernel to version 4.1.1 or greater.
You can find more information about CVE-2022-0882 at the following link: https://bugs.fuchsia.dev/p/fuchsia/issues/detail?id=94740