The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLServerDiscoverStreamsKM, and then copies the buffer to userspace. The method TLServerDiscoverStreamsKM may fail for several reasons including invalid sizes. If this method fails the buffer will be left uninitialized and despite the error will still be copied to userspace. Kernel leak of uninitialized heap data with no privs required.Product: AndroidVersions: Android SoCAndroid ID: A-236838960
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://source.android.com/security/bulletin/2022-08-01 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: google_android
Published: 2022-08-24T13:40:05
Updated: 2024-08-03T15:55:18.158Z
Reserved: 2020-11-06T00:00:00
Link: CVE-2021-0947
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-08-24T14:15:09.347
Modified: 2023-08-08T14:21:49.707
Link: CVE-2021-0947
Redhat
No data.