In multiple functions of mem_protect.c, there is a possible way to access hypervisor memory due to a memory access check in the wrong place. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
References
Configurations
History
21 Nov 2024, 07:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://android.googlesource.com/kernel/common/+/53625a846a7b4 - Patch | |
References | () https://android.googlesource.com/kernel/common/+/b35a06182451f - Patch | |
References | () https://source.android.com/security/bulletin/2023-08-01 - Patch, Vendor Advisory |
24 Aug 2023, 15:31
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.7 |
First Time |
Google
Google android |
|
CPE | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* | |
References | (MISC) https://source.android.com/security/bulletin/2023-08-01 - Patch, Vendor Advisory | |
References | (MISC) https://android.googlesource.com/kernel/common/+/b35a06182451f - Patch | |
References | (MISC) https://android.googlesource.com/kernel/common/+/53625a846a7b4 - Patch | |
CWE | CWE-119 |
14 Aug 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-14 21:15
Updated : 2024-11-21 07:42
NVD link : CVE-2023-21264
Mitre link : CVE-2023-21264
CVE.ORG link : CVE-2023-21264
JSON object : View
Products Affected
- android
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer