First published: Mon Dec 04 2023(Updated: )
In modify_for_next_stage of fdt.rs, there is a possible way to render KASLR ineffective due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Credit: security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | =14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40082 is a vulnerability in the modify_for_next_stage function of fdt.rs in Google Android that allows an attacker to render Kernel Address Space Layout Randomization (KASLR) ineffective, leading to remote escalation of privilege without requiring additional execution privileges.
The severity of CVE-2023-40082 is high with a CVSSv3 score of 7 out of 10.
CVE-2023-40082 can be exploited remotely without requiring user interaction.
Google Android is affected by CVE-2023-40082.
To fix CVE-2023-40082, users should apply the security patch provided by Google for Android.