CVE-2023-35685

In DevmemIntMapPages of devicemem_server.c, there is a possible physicalpage uaf due to a logic error in the code. This could lead to localescalation of privilege in the kernel with no additional executionprivileges needed. User interaction is not needed for exploitation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
google_androidCNA
---
---
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
VendorProductVersion
googleandroid
-
𝑥
= Vulnerable software versions