CVE Vulnerabilities

CVE-2022-20127

Double Free

Published: Jun 15, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In ce_t4t_data_cback of ce_t4t.cc, there is a possible out of bounds write due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-221862119

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle10.0 (including)10.0 (including)
AndroidGoogle11.0 (including)11.0 (including)
AndroidGoogle12.0 (including)12.0 (including)
AndroidGoogle12.1 (including)12.1 (including)

Potential Mitigations

References