In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
oryginał ENCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HGoogle Android
OSGooglewszystkie wersjeHuawei Berkeley L09
HWHuaweiwszystkie wersjeHuawei Berkeley L09 Firmware
OSHuawei< 10.0.0.177\(c10e3r1p4\)Huawei Columbia Al10b
HWHuaweiwszystkie wersjeHuawei Columbia Al10b Firmware
OSHuawei< 10.0.0.178\(c00e178r1p4\)Huawei Columbia L29d
HWHuaweiwszystkie wersjeHuawei Columbia L29d Firmware
OSHuawei< 10.0.0.177\(c10e4r1p4\)< 10.0.0.177\(c432e3r1p4\)Huawei Columbia Tl00b
HWHuaweiwszystkie wersjeHuawei Columbia Tl00b Firmware
OSHuawei< 10.0.0.178\(c01e178r1p4\)Huawei Columbia Tl00d
HWHuaweiwszystkie wersjeHuawei Columbia Tl00d Firmware
OSHuawei< 10.0.0.178\(c01e178r1p4\)Huawei Cornell Al00a
HWHuaweiwszystkie wersjeHuawei Cornell Al00a Firmware
OSHuawei< 9.1.0.340\(c00e333r1p1t8\)Huawei Cornell Tl10b
HWHuaweiwszystkie wersjeHuawei Cornell Tl10b Firmware
OSHuawei< 9.1.0.340\(c01e333r1p1t8\)Huawei Dura Al00a
HWHuaweiwszystkie wersjeHuawei Dura Al00a Firmware
OSHuawei< 1.0.0.190\(c00\)Huawei Honor 20 Pro
HWHuaweiwszystkie wersjeHuawei Honor 20 Pro Firmware
OSHuawei< 10.0.0.202\(c10e3r3p2\)< 10.0.0.194\(c636e3r3p1\)Huawei Honor 8a
HWHuaweiwszystkie wersjeHuawei Honor 8a Firmware
OSHuawei< 9.1.0.291\(c432e5r2p1\)< 9.1.0.291\(c636e4r4p1\)< 9.1.0.291\(c185e3r4p1\)< 9.1.0.297\(c605e4r4p2\)Huawei Honor View 20
HWHuaweiwszystkie wersjeHuawei Honor View 20 Firmware
OSHuawei< 10.0.0.201\(c10e5r4p3\)< 10.0.0.198\(c432e10r3p4\)< 10.0.0.200\(c185e3r3p3\)Huawei Jakarta Al00a
HWHuaweiwszystkie wersjeHuawei Jakarta Al00a Firmware
OSHuawei< 9.1.0.251\(c00e106r2p2\)Huawei Katyusha Al00a
HWHuaweiwszystkie wersjeHuawei Katyusha Al00a Firmware
OSHuawei< 9.1.0.146\(c00e131r2p2\)Huawei Katyusha Al10a
HWHuaweiwszystkie wersjeHuawei Katyusha Al10a Firmware
OSHuawei< 9.1.0.160\(c00e150r1p7\)Huawei Madrid Al00a
HWHuaweiwszystkie wersje
CISA KEV — szczegółyi
- Dostawcai
- MediaTek
- Produkti
- Multiple Chipsets
- Data dodania do KEVi
- 3 listopada 2021
- Termin remediation (USA)i
- 3 maja 2022(po terminie)
Zastosuj aktualizacje zgodnie z instrukcjami dostawcy.
▸ Pokaż oryginał (EN)
Apply updates per vendor instructions.
Wiele chipsetów MediaTek zawiera lukę o niedostatecznej walidacji danych wejściowych oraz brakujące ograniczenia SELinux w programach obsługi ioctl sterowników Command Queue. Prowadzi to do zapisu poza granicami pamięci prowadzącego do eskalacji uprawnień. Ta luka została zaobserwowana w łańcuchu exploitów z CVE-2019-2215 i CVE-2020-0041 pod nazwą "AbstractEmu".
▸ Pokaż oryginał (EN)
Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."
Powiązane podatności
Heap buffer overflow w Google Chrome na Android — sandbox escape
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...