CVE-2024-47039: OOB Read in the android.hardware.boot.IBootControl/default service
Published Dec 18, 2024
·Updated
In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Software
2 affected components
Android IBootControl
Google Android=10.0
Event History
Dec 18, 2024
CVE Published
via MITRE·07:04 PM
Data Sourced
via MITRE·07:04 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47039?
CVE-2024-47039 has a medium severity rating due to the potential for local information disclosure.
2
How do I fix CVE-2024-47039?
To fix CVE-2024-47039, update your affected Android devices to the latest software version provided by the manufacturer.
3
What type of vulnerability is CVE-2024-47039?
CVE-2024-47039 is a vulnerability characterized by a possible out-of-bounds read, resulting from a missing bounds check.
4
Does CVE-2024-47039 require user interaction for exploitation?
No, CVE-2024-47039 does not require user interaction for exploitation.
5
Which software is affected by CVE-2024-47039?
CVE-2024-47039 affects the Android IBootControl component.