First published: Mon Oct 03 2022(Updated: )
In fdt_next_tag of fdt.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-230794395
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =10.0 | |
Google Android | =11.0 | |
Google Android | =12.0 | |
Google Android | =12.1 | |
Google Android | =13.0 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-20412 has a severity level that allows for local escalation of privilege with system execution privileges needed.
Fixing CVE-2022-20412 requires applying the latest security updates provided by Android for affected versions.
CVE-2022-20412 affects Android 10, 11, 12, 12.1, and 13.
No user interaction is required for exploiting CVE-2022-20412.
The potential impact of CVE-2022-20412 includes an out of bounds read leading to local privilege escalation.