CVE-2024-32922
Last modified
CVE-2024-32922 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. In gpu_pm_power_on_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. EPSS estimates a 0.08% chance of exploitation in the next 30 days.
Description
In gpu_pm_power_on_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local escalation of privilege to TEE with no additional execution privileges needed. User interaction is not needed for exploitation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-32922?
How severe is CVE-2024-32922?
How do I fix CVE-2024-32922?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-32917In pl330_dma_from_peri_start() of fp_spi_dma.c, there is a p…7.1
- CVE-2024-32918Permission Bypass allowing attackers to disable HDCP 2.2 en…6.1
- CVE-2024-32919In lwis_add_completion_fence of lwis_fence.c, there is a pos…7.8
- CVE-2024-3292A race condition vulnerability exists where an authenticated…8.2
- CVE-2024-32920In set_secure_reg of sac_handler.c, there is a possible out …7.1
- CVE-2024-32921In lwis_initialize_transaction_fences of lwis_fence.c, there…7.4
- CVE-2024-32923there is a possible cellular denial of service due to a logi…4
- CVE-2024-32924In DeregAcceptProcINT of cn_NrmmStateDeregInit.cpp, there is…7.5
- CVE-2024-32925In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a pos…8.8
- CVE-2024-32926there is a possible information disclosure due to side chann…5.5
- CVE-2024-32927In sendDeviceState_1_6 of RadioExt.cpp, there is a possible …7.8
- CVE-2024-32928The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a …5.9
Are you affected by CVE-2024-32922?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
