CVE-2022-20122

The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232441339
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

History

29 Aug 2022, 01:03

Type Values Removed Values Added
First Time Google android
Google
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-416
CPE cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
References (MISC) https://source.android.com/security/bulletin/2022-08-01 - (MISC) https://source.android.com/security/bulletin/2022-08-01 - Vendor Advisory

24 Aug 2022, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-08-24 14:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-20122

Mitre link : CVE-2022-20122

CVE.ORG link : CVE-2022-20122


JSON object : View

Products Affected

google

  • android
CWE
CWE-416

Use After Free