Impact
An out-of-bounds memory read/write flaw in the Android kernel’s iommu.c driver allows a local attacker to read or overwrite memory beyond intended bounds due to improper input validation. The vulnerability is a classic input validation failure (CWE-20) that gives the attacker the ability to gain kernel level privileges without needing any additional execution privileges.
Affected Systems
Google Android devices that utilize the Android kernel common repository containing the vulnerable iommu.c code are affected. Any build prior to the latest patched release, meaning current and older devices that have not applied the fix, are susceptible. No specific device model or OS version is listed, so all Android installations using the affected kernel component are potentially vulnerable.
Risk and Exploitability
The flaw scores 7.8 on CVSS, categorizing it as high severity. It requires only local access and no user interaction, meaning a legitimate user or an attacker with local privileges can trigger it with minimal effort. The EPSS is <1%, indicating a low probability of exploitation in the wild, and it is not listed in CISA KEV. Nonetheless, the risk is significant because the vulnerability permits full kernel privilege escalation, which can be leveraged for a range of destructive actions if a local attacker is present.
OpenCVE Enrichment