The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read. However, given that the OOB read value is ending up as the address field of a struct I think i seems plausible that this could lead to an OOB write if the attacker is able to cause the OOB read to pull an interesting kernel address. Regardless if this is a read or write, it is a High severity issue in the kernel.Product: AndroidVersions: Android SoCAndroid ID: A-238904312
More Stories
mysql8.0-8.0.41-1.fc41
FEDORA-2025-8352a35e30 Packages in this update: mysql8.0-8.0.41-1.fc41 Update description: MySQL 8.0.41 Reease notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-41.html Read More
mysql8.0-8.0.41-1.fc40
FEDORA-2025-ebdcfc0f27 Packages in this update: mysql8.0-8.0.41-1.fc40 Update description: MySQL 8.0.41 Reease notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-41.html Read More
workrave-1.11.0~rc.1-1.el9
FEDORA-EPEL-2025-85c41364aa Packages in this update: workrave-1.11.0~rc.1-1.el9 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc41
FEDORA-2025-d611c8d114 Packages in this update: workrave-1.11.0~rc.1-1.fc41 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc42
FEDORA-2025-85867bd98f Packages in this update: workrave-1.11.0~rc.1-1.fc42 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc40
FEDORA-2025-2d5726abb8 Packages in this update: workrave-1.11.0~rc.1-1.fc40 Update description: Unretireing the package. Read More