Vulnerability CVE-2021-22556


Published: 2022-05-03

Description:
The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache invalidation operations on pages that they don??t own, allowing them to control kernel memory from userspace. We recommend upgrading to kernel version 4.1 or beyond.

Type:

CWE-190

(Integer Overflow or Wraparound)

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Google -> Fuchsia 

 References:
https://fuchsia-review.googlesource.com/c/fuchsia/+/570881
https://fuchsia.dev/whats-new/release-notes/f4-1

Copyright 2024, cxsecurity.com

 

Back to Top