In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
Fri, 25 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android Google pixel |
|
Weaknesses | CWE-22 | |
CPEs | cpe:2.3:h:google:pixel:*:*:*:*:*:*:*:* cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Google
Google android Google pixel |
|
Metrics |
cvssV3_1
|
Fri, 25 Oct 2024 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: Google_Devices
Published: 2024-10-25T10:34:06.522Z
Updated: 2024-10-25T16:12:48.479Z
Reserved: 2024-09-16T19:14:14.860Z
Link: CVE-2024-47027
Vulnrichment
Updated: 2024-10-25T16:06:49.573Z
NVD
Status : Analyzed
Published: 2024-10-25T11:15:17.220
Modified: 2024-10-28T17:58:46.217
Link: CVE-2024-47027
Redhat
No data.