CVE-2022-20008

MEDIUM

Android - Local Information Disclosure via Uninitialized Data in mmc_blk_read_single

Title source: llm
STIX 2.1

Description

In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216481035References: Upstream kernel

References (1)

Core 1
Core References

Scores

CVSS v3 4.6
EPSS 0.0036
EPSS Percentile 27.4%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-908
Status published
Products (1)
google/android
Published May 10, 2022
Tracked Since Feb 18, 2026