3.3
CVE-2023-22808
- EPSS 0.08%
- Veröffentlicht 11.04.2023 21:15:17
- Zuletzt bearbeitet 11.02.2025 21:15:11
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arm ≫ Avalon Android Gralloc Module Versionr41p0
Arm ≫ Bifrost Android Gralloc Module Version >= r24p0 <= r41p0
Arm ≫ Valhall Android Gralloc Module Version >= r24p0 <= r41p0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.238 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.