CVE-2022-20140 (High) detected in btandroid-10.0.0_r33
mend-bolt-for-github opened this issue · 0 comments
mend-bolt-for-github commented
CVE-2022-20140 - High Severity Vulnerability
Vulnerable Library - btandroid-10.0.0_r33
Library home page: https://android.googlesource.com/platform/system/bt
Found in base branch: master
Vulnerability Details
In read_multi_rsp of gatt_sr.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-227618988
Publish Date: 2022-06-15
URL: CVE-2022-20140
CVSS 3 Score Details (9.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: https://source.android.com/security/bulletin/2022-06-01
Release Date: 2022-06-15
Fix Resolution: android-12.1.0_r7
Step up your Open Source Security Game with Mend here