'remappfnrange' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vmpageprot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploited
{ "spl": "2022-07-05", "severity": "High", "types": [ "EoP" ] }
"https://storage.googleapis.com/android-osv/ASB-A-233154555.json"