Description
In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr" is a static variable, of type "struct crus_sp_ioctl_header".Product: AndroidVersions: Android kernelAndroid ID: A-135129430
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-1738 | In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr" is a static variable, of type "struct crus_sp_ioctl_header".Product: AndroidVersions: Android kernelAndroid ID: A-135129430 |
References
History
No history.
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2024-08-04T05:55:12.554Z
Reserved: 2019-10-17T00:00:00.000Z
Link: CVE-2020-0235
No data.
Status : Modified
Published: 2020-06-16T14:15:10.713
Modified: 2024-11-21T04:53:09.430
Link: CVE-2020-0235
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD