SB2023070536 - Multiple vulnerabilities in Google Pixel



SB2023070536 - Multiple vulnerabilities in Google Pixel

Published: July 5, 2023

Security Bulletin ID SB2023070536
Severity
Low
Patch available
YES
Number of vulnerabilities 14
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 14 secuirty vulnerabilities.


1) Improper input validation (CVE-ID: CVE-2023-21400)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Kernel io_uring subcomponent in Kernel components. A local application can execute arbitrary code.


2) Improper input validation (CVE-ID: CVE-2023-35693)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Incremental File System (IncFS) subcomponent in Kernel components. A local application can execute arbitrary code.


3) Improper input validation (CVE-ID: CVE-2023-21399)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the GSC subcomponent in Pixel. A local application can execute arbitrary code.


4) Improper input validation (CVE-ID: CVE-2023-35691)

The vulnerability allows a local application to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Titan M subcomponent in Pixel. A local application can perform a denial of service (DoS) attack.


5) Improper input validation (CVE-ID: CVE-2023-35692)

The vulnerability allows a local application to execute arbitrary code.

The vulnerability exists due to improper input validation within the Telephony subcomponent in Pixel. A local application can execute arbitrary code.


6) Information exposure (CVE-ID: CVE-2023-35694)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation within the samsung_slsi subcomponent in Pixel. A local application can gain access to sensitive information.


7) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2023-21641)

The vulnerability allows a local application to read, manipulate or delete data.

The vulnerability exists due to improper input validation in Display. A local application can read, manipulate or delete data.


8) Information exposure (CVE-ID: CVE-2023-21624)

The vulnerability allows a local application to gain access to sensitive information.

The vulnerability exists due to improper input validation in DSP Services. A local application can gain access to sensitive information.


9) Memory corruption (CVE-ID: CVE-2023-21633)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Linux. A local privileged application can execute arbitrary code.


10) Buffer overflow (CVE-ID: CVE-2023-21635)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Data Network Stack & Connectivity. A local privileged application can execute arbitrary code.


11) Memory corruption (CVE-ID: CVE-2023-21637)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Linux. A local privileged application can execute arbitrary code.


12) Type conversion (CVE-ID: CVE-2023-21638)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Video. A local privileged application can execute arbitrary code.


13) Buffer overflow (CVE-ID: CVE-2023-21639)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Audio. A local privileged application can execute arbitrary code.


14) Buffer overflow (CVE-ID: CVE-2023-21640)

The vulnerability allows a local privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in Linux. A local privileged application can execute arbitrary code.


Remediation

Install update from vendor's website.