Google LLC Vulnerabilities and Affected Products
Vulnerabilities associated with Fuchsia Kernel.
Products
Clear product- Asylo16 vulnerabilities
- Dart SDK4 vulnerabilities
- fscrypt3 vulnerabilities
- guest-oslogin3 vulnerabilities
- AWS S3 Crypto SDK for GoLang2 vulnerabilities
- Fuchsia2 vulnerabilities
- Fuchsia Kernel2 vulnerabilities
- libjxl2 vulnerabilities
- Android Play Core1 vulnerability
- Bazel1 vulnerability
- Bindiff1 vulnerability
- Brotli1 vulnerability
- Dart1 vulnerability
- Data-Transfer-Project1 vulnerability
- Drive for Desktop MacOS1 vulnerability
- Exposure Notifications Verification Server1 vulnerability
- Gerrit1 vulnerability
- go-attestation1 vulnerability
- Google Cloud IoT Device SDK for Embedded C1 vulnerability
- Google Earth Pro1 vulnerability
- Google Exposure-notifications-verification-server1 vulnerability
- Google Play Services SDK1 vulnerability
- Google-oauth-java-client1 vulnerability
- google-protobuf [JRuby Gem]1 vulnerability
- google/go-tpm library1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-0882MEDIUM | Illegal access to Kernel log in FuchsiaA bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capability ZX_RSRC_KIND_ROOT. It is recommended to upgrade the Fuchsia kernel to 4.1.1 or greater. CWE-200May 3, 2022 | CVSS5.3v3.1 | EPSS0.115% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-22556MEDIUM | Integer Overflow in Fuchsia KernelThe Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache invalidation operations on pages that they don’t own, allowing them to control kernel memory from userspace. We recommend upgrading to kernel version 4.1 or beyond. CWE-190May 3, 2022 | CVSS5.3v3.1 | EPSS0.155% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |