VDB

CISA-2024-23698

CISA-2024-23698 PUBLISHED CVSS 7.8 HIGH

Reported by google_android · Published July 9, 2024

In RGXFWChangeOSidPriority of rgxfwutils.c, there is a possible arbitrary code execution due to a missing bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

Risk Scores

CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
GoogleAndroidAndroid SoC
imaginationtechpowervr-gpu0, 0
GoogleAndroidAndroid SoC, Android SoC

Timeline

  • Jul 9, 2024 CVE Published
  • Aug 1, 2024 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›