First published: Fri Feb 11 2022(Updated: )
An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.
Credit: mobile.security@samsung.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =10.0 | |
Google Android | =11.0 | |
Google Android | =12.0 | |
Samsung Exynos |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23432 is a vulnerability in the SMC_SRPMB_WSM handler of RPMB ldfw that allows arbitrary memory write and code execution.
CVE-2022-23432 has a severity rating of 6.7 (medium).
CVE-2022-23432 affects Google Android versions 10.0, 11.0, and 12.0.
To fix CVE-2022-23432, apply the SMR Feb-2022 Release 1 update available from the Samsung security update website.
No, Samsung Exynos is not vulnerable to CVE-2022-23432.