CVE-2022-42505
Last modified
CVE-2022-42505 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. In ProtocolMiscBuilder::BuildSetSignalReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
In ProtocolMiscBuilder::BuildSetSignalReportCriteria of protocolmiscbuilder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241232492References: N/A
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-42505?
How severe is CVE-2022-42505?
How do I fix CVE-2022-42505?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-4250A vulnerability has been found in Movie Ticket Booking Syste…6.1
- CVE-2022-42500In OEM_OnRequest of sced.cpp, there is a possible shell comm…6.7
- CVE-2022-42501In HexString2Value of util.cpp, there is a possible out of b…6.7
- CVE-2022-42502In FacilityLock::Parse of simdata.cpp, there is a possible o…6.7
- CVE-2022-42503In ProtocolMiscBuilder::BuildSetLinkCapaReportCriteria of pr…6.7
- CVE-2022-42504In CallDialReqData::encodeCallNumber of callreqdata.cpp, the…6.7
- CVE-2022-42506In SimUpdatePbEntry::encode of simdata.cpp, there is a possi…6.7
- CVE-2022-42507In ProtocolSimBuilder::BuildSimUpdatePb3gEntry of protocolsi…6.7
- CVE-2022-42508In ProtocolCallBuilder::BuildSendUssd of protocolcallbuilder…6.7
- CVE-2022-42509In CallDialReqData::encode of callreqdata.cpp, there is a po…6.7
- CVE-2022-4251A vulnerability was found in Movie Ticket Booking System and…5.4
- CVE-2022-42510In StringsRequestData::encode of requestdata.cpp, there is a…6.7
Are you affected by CVE-2022-42505?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
