In the Android kernel in the f2fs driver there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Sep 6, 2019 |
| Ubuntu | — | Upgrade linux-oracleUpgrade linux-raspi2Upgrade linux-kvmUpgrade linux-gcpUpgrade linux-aws-fipsUpgrade linux-fipsUpgrade linux-aws-hweUpgrade linux-awsUpgrade linux-azure-fipsUpgrade linuxUpgrade linux-gke-4.15Upgrade linux-oemUpgrade linux-snapdragonUpgrade linux-azureUpgrade linux-hwe | Nov 19, 2024 | Sep 6, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub