CVE-2024-31335

July 9, 2024, 9:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Linux Kernel

Source

security@android.com

Tags

CVE-2024-31335 details

Published : July 9, 2024, 9:15 p.m.
Last Modified : July 9, 2024, 9:15 p.m.

Description

In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description

References

URL Source
https://source.android.com/security/bulletin/2024-07-01 security@android.com
This website uses the NVD API, but is not approved or certified by it.