CVE Vulnerabilities

CVE-2022-20499

Published: Mar 24, 2023 | Modified: Feb 28, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-246539931

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle12.0 (including)12.0 (including)
AndroidGoogle12.1 (including)12.1 (including)
AndroidGoogle13.0 (including)13.0 (including)
Android-platform-frameworks-baseUbuntubionic*
Android-platform-frameworks-baseUbuntudevel*
Android-platform-frameworks-baseUbuntuesm-apps/bionic*
Android-platform-frameworks-baseUbuntuesm-apps/focal*
Android-platform-frameworks-baseUbuntuesm-apps/jammy*
Android-platform-frameworks-baseUbuntuesm-apps/noble*
Android-platform-frameworks-baseUbuntuesm-apps/xenial*
Android-platform-frameworks-baseUbuntufocal*
Android-platform-frameworks-baseUbuntujammy*
Android-platform-frameworks-baseUbuntukinetic*
Android-platform-frameworks-baseUbuntulunar*
Android-platform-frameworks-baseUbuntumantic*
Android-platform-frameworks-baseUbuntunoble*
Android-platform-frameworks-baseUbuntuoracular*
Android-platform-frameworks-baseUbuntutrusty*
Android-platform-frameworks-baseUbuntuxenial*

References