In setPowerMode of HWC2.cpp, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-242688355
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | 13.0 (including) | 13.0 (including) | |
Android-platform-frameworks-native | Ubuntu | bionic | * |
Android-platform-frameworks-native | Ubuntu | devel | * |
Android-platform-frameworks-native | Ubuntu | esm-apps/bionic | * |
Android-platform-frameworks-native | Ubuntu | esm-apps/focal | * |
Android-platform-frameworks-native | Ubuntu | esm-apps/jammy | * |
Android-platform-frameworks-native | Ubuntu | esm-apps/noble | * |
Android-platform-frameworks-native | Ubuntu | esm-apps/xenial | * |
Android-platform-frameworks-native | Ubuntu | focal | * |
Android-platform-frameworks-native | Ubuntu | jammy | * |
Android-platform-frameworks-native | Ubuntu | kinetic | * |
Android-platform-frameworks-native | Ubuntu | lunar | * |
Android-platform-frameworks-native | Ubuntu | mantic | * |
Android-platform-frameworks-native | Ubuntu | noble | * |
Android-platform-frameworks-native | Ubuntu | oracular | * |
Android-platform-frameworks-native | Ubuntu | trusty | * |
Android-platform-frameworks-native | Ubuntu | xenial | * |
Android-platform-tools | Ubuntu | devel | * |
Android-platform-tools | Ubuntu | esm-apps/jammy | * |
Android-platform-tools | Ubuntu | esm-apps/noble | * |
Android-platform-tools | Ubuntu | jammy | * |
Android-platform-tools | Ubuntu | kinetic | * |
Android-platform-tools | Ubuntu | lunar | * |
Android-platform-tools | Ubuntu | mantic | * |
Android-platform-tools | Ubuntu | noble | * |
Android-platform-tools | Ubuntu | oracular | * |
Android-platform-tools | Ubuntu | trusty | * |
Android-platform-tools | Ubuntu | xenial | * |