An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the listed versions.
References
Link | Resource |
---|---|
https://fuchsia.googlesource.com/fuchsia/+/d97c05d2301799ed585620a9c5c739d36e7b5d3d | Mailing List Patch Vendor Advisory |
https://fuchsia.googlesource.com/fuchsia/+/d97c05d2301799ed585620a9c5c739d36e7b5d3d | Mailing List Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 06:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://fuchsia.googlesource.com/fuchsia/+/d97c05d2301799ed585620a9c5c739d36e7b5d3d - Mailing List, Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 2.1
v3 : 7.5 |
Information
Published : 2022-02-25 11:15
Updated : 2024-11-21 06:38
NVD link : CVE-2022-0247
Mitre link : CVE-2022-0247
CVE.ORG link : CVE-2022-0247
JSON object : View
Products Affected
- fuchsia
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource