In CacheOpPMRExec of cache_km.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/2024-06-01 | Vendor Advisory |
https://source.android.com/security/bulletin/2024-06-01 | Vendor Advisory |
Configurations
History
17 Dec 2024, 16:52
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* | |
References | () https://source.android.com/security/bulletin/2024-06-01 - Vendor Advisory | |
First Time |
Google android
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
Information
Published : 2024-07-09 21:15
Updated : 2024-12-17 16:52
NVD link : CVE-2024-23695
Mitre link : CVE-2024-23695
CVE.ORG link : CVE-2024-23695
JSON object : View
Products Affected
- android
CWE
CWE-190
Integer Overflow or Wraparound