CVE-2023-22808
LOWARM Avalon Android Gralloc Module < r41p0 - Out-of-Bounds Read
Title source: ruleDescription
An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
References (1)
Core 1
Core References
Scores
CVSS v3
3.3
EPSS
0.0025
EPSS Percentile
48.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (3)
arm/avalon_android_gralloc_module
r41p0
arm/bifrost_android_gralloc_module
r24p0 - r41p0
arm/valhall_android_gralloc_module
r24p0 - r41p0
Published
Apr 11, 2023
Tracked Since
Feb 18, 2026