CVE-2022-23431: Medium severity android vulnerability
Published Feb 11, 2022
·Updated
An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
Affected Software
4 affected components
Google Android=10.0
Google Android=11.0
Google Android=12.0
Samsung Exynos
Event History
Feb 11, 2022
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability?
The vulnerability is an improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 that allows arbitrary memory write and code execution.
2
What software versions are affected by CVE-2022-23431?
Google Android versions 10.0, 11.0, and 12.0 are affected by CVE-2022-23431.
3
What is the severity of CVE-2022-23431?
The severity of CVE-2022-23431 is medium with a severity value of 6.7.
4
How can I fix CVE-2022-23431?
To fix CVE-2022-23431, update to SMR Feb-2022 Release 1 or a newer version as provided by the vendor.
5
Where can I find more information about CVE-2022-23431?
You can find more information about CVE-2022-23431 at the following reference link: [Security Update from Samsung](https://security.samsungmobile.com/securityUpdate.smsb?year=2022&month=2)