CVE-2024-25986

HIGH

Android - Memory Corruption in drm_fw.c ppmp_unprotect_buf

Title source: llm
STIX 2.1

Description

In ppmp_unprotect_buf of drm_fw.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0004
EPSS Percentile 12.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119
Status published
Products (1)
google/android 13.0
Published Mar 11, 2024
Tracked Since Feb 18, 2026