VDB
ASB-A-197154735
ASB-A-197154735
PUBLISHED
CVSS 6.900000095367432 MEDIUM
In sctp_v6_to_sk_daddr, sctp_v4_from_addr_param, and related functions of ipv6.c, protocol.c, and related files, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure to an on-path attacker with no additional execution privileges needed. User interaction is not needed for exploitation.
Risk Scores
CVSS 4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | :linux_kernel: | :0, Kernel, :0 |
Timeline
- Mar 1, 2022 CVE Published
- May 15, 2026 CVE Updated
References
- https://source.android.com/security/bulletin/2022-03-01 advisory
- https://android.googlesource.com/kernel/common/+/d4dbef7046e2 patch
- https://android.googlesource.com/kernel/common/+/6ef81a5c0e22 patch
- https://android.googlesource.com/kernel/common/+/ffca46766850 patch
- https://android.googlesource.com/kernel/common/+/ccb79116c372 patch