In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Tue, 20 Aug 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-20 |
MITRE
Status: PUBLISHED
Assigner: Google_Devices
Published: 2024-06-13T21:01:58.676Z
Updated: 2024-08-20T17:51:49.942Z
Reserved: 2024-04-19T15:00:32.963Z
Link: CVE-2024-32903
Vulnrichment
Updated: 2024-08-02T02:20:35.656Z
NVD
Status : Modified
Published: 2024-06-13T21:15:54.583
Modified: 2024-11-21T09:15:59.150
Link: CVE-2024-32903
Redhat
No data.