CVE-2022-20069: Integer Overflow
In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege, for an attacker who has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06160425; Issue ID: ALPS06160425.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-20069?
CVE-2022-20069 is a vulnerability in the preloader (usb) component that allows for an out of bounds write due to an integer overflow.
What is the severity of CVE-2022-20069?
The severity of CVE-2022-20069 is medium with a CVSS score of 6.6.
Which software versions are affected by CVE-2022-20069?
CVE-2022-20069 affects Google Android versions 10.0, 11.0, and 12.0.
How can an attacker exploit CVE-2022-20069?
To exploit CVE-2022-20069, an attacker would need physical access to the device and user interaction.
How can I fix CVE-2022-20069?
To fix CVE-2022-20069, apply the patch provided by ALPS and refer to the product security bulletin for more information.