SB2022090807 - Multuiple vulnerabilities in Google Pixel
Published: September 8, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) Double Free (CVE-ID: CVE-2022-28388)
The vulnerability allows a local user to execute arbitrary code with elevated privileges.
The vulnerability exists due to boundary error in the usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c. A local user can pass specially crafted data to the application, trigger double free error and execute arbitrary code with elevated privileges.
2) Buffer overflow (CVE-ID: CVE-2022-25654)
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error when processing ION commands within kernel. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.
3) Out-of-bounds read (CVE-ID: CVE-2022-25653)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing AVI files. A remote attacker can create a specially crafted AVI file, trick the victim into playing it, trigger an out-of-bounds read error and read contents of memory on the system or crash the application.
4) Buffer overflow (CVE-ID: CVE-2022-20231)
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error within the Trusty component. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.
5) Buffer overflow (CVE-ID: CVE-2022-20364)
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error within the kernel component. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.
Remediation
Install update from vendor's website.