3.3
CVE-2023-22808
- EPSS 0.08%
- Published 11.04.2023 21:15:17
- Last modified 11.02.2025 21:15:11
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
Data is provided by the National Vulnerability Database (NVD)
Arm ≫ Avalon Android Gralloc Module Versionr41p0
Arm ≫ Bifrost Android Gralloc Module Version >= r24p0 <= r41p0
Arm ≫ Valhall Android Gralloc Module Version >= r24p0 <= r41p0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.08% | 0.204 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.