CVE-2020-0186
Last modified
CVE-2020-0186 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. In hal_fd_init of hal_fd.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
In hal_fd_init of hal_fd.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146144463
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 10.0 |
References
- https://source.android.com/security/bulletin/pixel/2020-06-01Patch, Vendor Advisory
- https://source.android.com/security/bulletin/pixel/2020-06-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-0186?
How severe is CVE-2020-0186?
How do I fix CVE-2020-0186?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-0180In GetOpusHeaderBuffers() of OpusHeader.cpp, there is a poss…6.5
- CVE-2020-0181In exif_data_load_data_thumbnail of exif-data.c, there is a …7.5
- CVE-2020-0182In exif_entry_get_value of exif-entry.c, there is a possible…6.5
- CVE-2020-0183In handleMessage of BluetoothManagerService, there is an inc…7.8
- CVE-2020-0184In ihevcd_ref_list() of ihevcd_ref_list.c, there is a possib…6.5
- CVE-2020-0185In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a pos…5.5
- CVE-2020-0187In engineSetMode of BaseBlockCipher.java, there is a possibl…5.5
- CVE-2020-0188In onCreatePermissionRequest of SettingsSliceProvider.java, …7.8
- CVE-2020-0189In ihevcd_decode() of ihevcd_decode.c, there is possible res…6.5
- CVE-2020-0190In ideint_weave_blk of ideint_utils.c, there is a possible o…8.8
- CVE-2020-0191In ih264d_update_default_index_list() of ih264d_dpb_mgr.c, t…6.5
- CVE-2020-0192In ih264d_decode_slice_thread of ih264d_thread_parse_decode.…6.5
Are you affected by CVE-2020-0186?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
