CVE-2022-20008
Summary
| CVE | CVE-2022-20008 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-10 20:15:00 UTC |
| Updated | 2022-05-16 16:04:00 UTC |
| Description | In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216481035References: Upstream kernel |
Risk And Classification
Problem Types: CWE-908
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Android Security Bulletin—May 2022 | Android Open Source Project | MISC | source.android.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179262 Debian Security Update for linux (CVE-2022-20008)
- 198782 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5417-1)
- 198785 Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5415-1)
- 376925 Alibaba Cloud Linux Security Update for cloud-kernel (ALINUX3-SA-2022:0125)
- 610413 Google Android Devices May 2022 Security Patch Missing
- 610419 Google Android June 2022 Security Patch Missing for Samsung
- 610420 Google Android June 2022 Security Patch Missing for Huawei EMUI
- 671915 EulerOS Security Update for kernel (EulerOS-SA-2022-1969)
- 671975 EulerOS Security Update for kernel (EulerOS-SA-2022-2159)
- 672045 EulerOS Security Update for kernel (EulerOS-SA-2022-2225)
- 672391 EulerOS Security Update for kernel (EulerOS-SA-2022-2767)
- 672653 EulerOS Security Update for kernel (EulerOS-SA-2023-1388)
- 752228 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2078-1)
- 752669 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3587-1)
- 752671 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3584-1)
- 752702 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3693-1)
- 752708 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3704-1)
- 752724 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3775-1)
- 753296 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2177-1)
- 753368 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:2079-1)