CVE-2022-26095: Null Pointer Dereference
Published Apr 11, 2022
·Updated
Null pointer dereference vulnerability in parsercolr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
Affected Software
3 affected components
Google Android=10.0
Google Android=11.0
Google Android=12.0
Event History
Apr 11, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-26095?
CVE-2022-26095 is a null pointer dereference vulnerability in the parser_colr function in the libsimba library prior to SMR Apr-2022 Release 1.
2
How does CVE-2022-26095 affect the libsimba library?
CVE-2022-26095 allows a remote attacker to perform an out-of-bounds write in the libsimba library.
3
Which software versions are affected by CVE-2022-26095?
CVE-2022-26095 affects Google Android versions 10.0, 11.0, and 12.0.
4
What is the severity of CVE-2022-26095?
CVE-2022-26095 has a severity rating of critical with a CVSS score of 9.8.
5
Is there a fix available for CVE-2022-26095?
A fix for CVE-2022-26095 is included in the SMR Apr-2022 Release 1.