CVE-2022-20008
Vulnerability Summary
Timeline
Description
In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This could lead to local information disclosure if reading from an SD card that triggers errors, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216481035References: Upstream kernel
CVSS Metrics
- v4.0•LOW•Score: 2.4CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- v3.1•MEDIUM•Score: 4.6CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 0.36%• Percentile: 30%
Techniques & Countermeasures
- CWE-908•Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.
Affected Systems
- debian•linux
< 5.10.103-1 | < 5.16.11-1 | < 5.16.11-1 | < 5.16.11-1
- ubuntu•linux
< 5.4.0-110.124
- ubuntu•linux-aws
< 5.4.0-1073.78
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
< 5.13.0-1023.25~20.04.1
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1075.80~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-fips
< 5.4.0-1073.78+fips1 | all
- ubuntu•linux-azure
all | < 5.4.0-1078.81
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
< 5.13.0-1023.27~20.04.1
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1078.81~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fips
< 5.4.0-1078.81+fips1 | all
- ubuntu•linux-bluefield
all | < 5.4.0-1040.44
- ubuntu•linux-fips
< 5.4.0-1049.55 | all
- ubuntu•linux-gcp
all | < 5.4.0-1073.78
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
< 5.13.0-1025.30~20.04.1
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1073.78~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-fips
< 5.4.0-1073.78+fips1 | all
- ubuntu•linux-gke
< 5.4.0-1071.76
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.4
< 5.4.0-1071.76~18.04.3
- ubuntu•linux-gkeop
< 5.4.0-1040.41
- ubuntu•linux-gkeop-5.4
< 5.4.0-1040.41~18.04.1
- ubuntu•linux-hwe
all
- ubuntu•linux-hwe-5.11
all
- ubuntu•linux-hwe-5.13
< 5.13.0-41.46~20.04.1
- ubuntu•linux-hwe-5.4
< 5.4.0-110.124~18.04.1
- ubuntu•linux-hwe-5.8
all
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-ibm
< 5.4.0-1021.23
- ubuntu•linux-ibm-5.4
< 5.4.0-1021.23~18.04.1
- ubuntu•linux-intel-5.13
all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-intel-iotg-5.15
< 5.15.0-1008.11~20.04.1
- ubuntu•linux-iot
< 5.4.0-1004.6
- ubuntu•linux-kvm
< 5.4.0-1063.66
- ubuntu•linux-oem
all
- ubuntu•linux-oem-5.10
all
- ubuntu•linux-oem-5.13
all
- ubuntu•linux-oem-5.14
< 5.14.0-1027.30
- ubuntu•linux-oem-5.6
all
Showing first 50 affected entries in server-rendered view.
References (7)
- https://source.android.com/security/bulletin/2022-05-01
- https://ubuntu.com/security/CVE-2022-20008
- https://git.kernel.org/linus/54309fde1a352ad2674ebba004a79f7d20b9f037
- https://ubuntu.com/security/notices/USN-5415-1
- https://ubuntu.com/security/notices/USN-5417-1
- https://www.cve.org/CVERecord?id=CVE-2022-20008
- https://security-tracker.debian.org/tracker/CVE-2022-20008