UBUNTU-CVE-2022-20502

Source
https://ubuntu.com/security/CVE-2022-20502
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-20502.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-20502
Upstream
Published
2022-12-13T16:15:00Z
Modified
2025-10-24T04:53:21Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222166527

References

Affected packages

Ubuntu:18.04:LTS
android-platform-art

Package

Name
android-platform-art
Purl
pkg:deb/ubuntu/android-platform-art@8.1.0+r23-3~18.04?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.1.0+r23-3~18.04

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "8.1.0+r23-3~18.04",
            "binary_name": "android-libart"
        },
        {
            "binary_version": "8.1.0+r23-3~18.04",
            "binary_name": "dexdump"
        },
        {
            "binary_version": "8.1.0+r23-3~18.04",
            "binary_name": "dexlist"
        },
        {
            "binary_version": "8.1.0+r23-3~18.04",
            "binary_name": "dmtracedump"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-20502.json"
Ubuntu:20.04:LTS
android-platform-art

Package

Name
android-platform-art
Purl
pkg:deb/ubuntu/android-platform-art@8.1.0+r23-3?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.1.0+r23-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "8.1.0+r23-3",
            "binary_name": "android-libart"
        },
        {
            "binary_version": "8.1.0+r23-3",
            "binary_name": "dexdump"
        },
        {
            "binary_version": "8.1.0+r23-3",
            "binary_name": "dexlist"
        },
        {
            "binary_version": "8.1.0+r23-3",
            "binary_name": "dmtracedump"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-20502.json"
Ubuntu:22.04:LTS
android-platform-art

Package

Name
android-platform-art
Purl
pkg:deb/ubuntu/android-platform-art@10.0.0+r36-3?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

10.*
10.0.0+r36-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "10.0.0+r36-3",
            "binary_name": "android-libart"
        },
        {
            "binary_version": "10.0.0+r36-3",
            "binary_name": "dexdump"
        },
        {
            "binary_version": "10.0.0+r36-3",
            "binary_name": "dexlist"
        },
        {
            "binary_version": "10.0.0+r36-3",
            "binary_name": "dmtracedump"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-20502.json"
android-platform-tools

Package

Name
android-platform-tools
Purl
pkg:deb/ubuntu/android-platform-tools@29.0.6-4ubuntu1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

29.*
29.0.6-3
29.0.6-4
29.0.6-4ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:29.0.6-4ubuntu1",
            "binary_name": "adb"
        },
        {
            "binary_version": "29.0.6-4ubuntu1",
            "binary_name": "dmtracedump"
        },
        {
            "binary_version": "29.0.6-4ubuntu1",
            "binary_name": "etc1tool"
        },
        {
            "binary_version": "1:29.0.6-4ubuntu1",
            "binary_name": "fastboot"
        },
        {
            "binary_version": "29.0.6-4ubuntu1",
            "binary_name": "hprof-conv"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-20502.json"
Ubuntu:24.04:LTS
android-platform-art

Package

Name
android-platform-art
Purl
pkg:deb/ubuntu/android-platform-art@14.0.0+r15-1ubuntu2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

13.*
13.0.0+r63-2
14.*
14.0.0+r15-1ubuntu1
14.0.0+r15-1ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "14.0.0+r15-1ubuntu2",
            "binary_name": "android-libart"
        },
        {
            "binary_version": "1:14.0.0+r15-1ubuntu2",
            "binary_name": "android-libnativebridge"
        },
        {
            "binary_version": "1:14.0.0+r15-1ubuntu2",
            "binary_name": "android-libnativeloader"
        },
        {
            "binary_version": "14.0.0+r15-1ubuntu2",
            "binary_name": "dexdump"
        },
        {
            "binary_version": "14.0.0+r15-1ubuntu2",
            "binary_name": "dexlist"
        },
        {
            "binary_version": "1:14.0.0+r15-1ubuntu2",
            "binary_name": "dmtracedump"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-20502.json"
android-platform-tools

Package

Name
android-platform-tools
Purl
pkg:deb/ubuntu/android-platform-tools@34.0.4-1build3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

33.*
33.0.3-2
34.*
34.0.4-1build2
34.0.4-1build3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "adb"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libbacktrace"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libbacktrace-dev"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libbase"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libbase-dev"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libcutils"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libcutils-dev"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-liblog"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-liblog-dev"
        },
        {
            "binary_version": "34.0.4-1build3",
            "binary_name": "android-libnativehelper"
        },
        {
            "binary_version": "34.0.4-1build3",
            "binary_name": "android-libnativehelper-dev"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libsparse"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libsparse-dev"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libutils"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libutils-dev"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libziparchive"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-libziparchive-dev"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-platform-frameworks-native-headers"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-platform-system-core-headers"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "android-sdk-libsparse-utils"
        },
        {
            "binary_version": "34.0.4-1build3",
            "binary_name": "etc1tool"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "fastboot"
        },
        {
            "binary_version": "34.0.4-1build3",
            "binary_name": "hprof-conv"
        },
        {
            "binary_version": "1:34.0.4-1build3",
            "binary_name": "mkbootimg"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-20502.json"