fuchsia-review.googlesource.com
https://fuchsia-review.googlesource.com/c/fuchsia/+/570881 CVE-2021-22556
MEDIUM
Integer Overflow in Fuchsia Kernel
Record summary
CVE-2021-22556 has a selected CVSS score of 5.3 (medium).
Description
The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache invalidation operations on pages that they don’t own, allowing them to control kernel memory from userspace. We recommend upgrading to kernel version 4.1 or beyond.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 21, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Fuchsia KernelBrowse Google LLC / Fuchsia Kernel | CVE List | Before 4.1 | affected |
References
3fuchsia.dev
https://fuchsia.dev/whats-new/release-notes/f4-1 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-22556