CVE-2022-20122

CRITICAL

PowerVR GPU driver - Memory Corruption

Title source: llm
STIX 2.1

Description

The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid ID: A-232441339

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0036
EPSS Percentile 27.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (1)
google/android
Published Aug 24, 2022
Tracked Since Feb 18, 2026