UBUNTU-CVE-2022-20502

Source
https://ubuntu.com/security/CVE-2022-20502
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-20502.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-20502
Related
  • CVE-2022-20502
Published
2022-12-13T16:15:00Z
Modified
2025-01-13T10:23:24Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222166527

References

Affected packages

Ubuntu:Pro:18.04:LTS / android-platform-art

Package

Name
android-platform-art
Purl
pkg:deb/ubuntu/android-platform-art@8.1.0+r23-3~18.04?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*

8.1.0+r23-3~18.04

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / android-platform-art

Package

Name
android-platform-art
Purl
pkg:deb/ubuntu/android-platform-art@8.1.0+r23-3?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*

8.1.0+r23-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / android-platform-art

Package

Name
android-platform-art
Purl
pkg:deb/ubuntu/android-platform-art@10.0.0+r36-3?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

10.*

10.0.0+r36-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / android-platform-tools

Package

Name
android-platform-tools
Purl
pkg:deb/ubuntu/android-platform-tools@29.0.6-4ubuntu1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

29.*

29.0.6-3
29.0.6-4
29.0.6-4ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / android-platform-art

Package

Name
android-platform-art
Purl
pkg:deb/ubuntu/android-platform-art@14.0.0+r15-1ubuntu2?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

14.*

14.0.0+r15-1ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / android-platform-tools

Package

Name
android-platform-tools
Purl
pkg:deb/ubuntu/android-platform-tools@34.0.4-1.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

34.*

34.0.4-1build3
34.0.4-1.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / android-platform-art

Package

Name
android-platform-art
Purl
pkg:deb/ubuntu/android-platform-art@14.0.0+r15-1ubuntu2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

13.*

13.0.0+r63-2

14.*

14.0.0+r15-1ubuntu1
14.0.0+r15-1ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / android-platform-tools

Package

Name
android-platform-tools
Purl
pkg:deb/ubuntu/android-platform-tools@34.0.4-1build3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

33.*

33.0.3-2

34.*

34.0.4-1build2
34.0.4-1build3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}