CVE-2022-20009

NameCVE-2022-20009
DescriptionIn various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-213172319References: Upstream kernel
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Notes

CVE-2022-20009 duplicate of CVE-2022-25375 and CVE-2022-25258, Android CNA contacted

Search for package or bug name: Reporting problems