Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-21106
HistoryMay 08, 2023 - 12:00 a.m.

CVE-2023-21106

2023-05-0800:00:00
ubuntu.com
ubuntu.com
14
adreno gpu driver
memory corruption
local privilege escalation
android kernel
qualcomm
upstream kernel

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

In adreno_set_param of adreno_gpu.c, there is a possible memory corruption
due to a double free. This could lead to local escalation of privilege with
no additional execution privileges needed. User interaction is not needed
for exploitation.Product: AndroidVersions: Android kernelAndroid ID:
A-265016072References: Upstream kernel

Notes

Author Note
sbeattie this affects the Qualcomm ARM Adreno GPU driver.
Rows per page:
1-10 of 151

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%