remap_pfn_range here may map out of size kernel memory (for example, may map the kernel area), and because the vma->vm_page_prot can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions: Android SoCAndroid ID: A-233972091
The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | - (including) | - (including) |