UBUNTU-CVE-2022-20369
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-20369
UBUNTU-CVE-2022-20369
Summary:
Details: In v4l2_m2m_querybuf of v4l2-mem2mem.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223375145References: Upstream kernel
References: https://ubuntu.com/security/CVE-2022-20369, https://git.kernel.org/linus/8310ca94075e784bbb06593cd6c068ee6b6e4ca6, https://ubuntu.com/security/notices/USN-5668-1, https://ubuntu.com/security/notices/USN-5677-1, https://ubuntu.com/security/notices/USN-5682-1, https://ubuntu.com/security/notices/USN-5706-1, https://ubuntu.com/security/notices/USN-5854-1, https://ubuntu.com/security/notices/USN-5861-1, https://ubuntu.com/security/notices/USN-5862-1, https://ubuntu.com/security/notices/USN-5865-1, https://ubuntu.com/security/notices/USN-5883-1, https://ubuntu.com/security/notices/USN-5924-1, https://ubuntu.com/security/notices/USN-5975-1, https://ubuntu.com/security/notices/USN-6007-1, https://www.cve.org/CVERecord?id=CVE-2022-20369
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/linux-azure?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
