Vulnerability

CVE-2022-20063

In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS06171715; Issue ID: ALPS06171715.

Impact

Severity (Manufact.)

MEDIUM

Severity (NIST)

6.5

Severity (Android)

N/A

Chipsets

4

Devices

217

Affected Hardware

NameAlso known asManufacturer
MT6765
Helio P35
MediaTek
MT6765G
Helio G35
MediaTek
MT6765H
Helio G37
MediaTek
MT6765V/XBA
Helio G36
MediaTek
4 of 4 row(s) shown.

Rows per page

Page 1 of 1

Timeline

Introduced (est):
Oct 1, 2018
Reported:
Unknown
Advisory Published:
Apr 6, 2022
CVE Published:
Apr 11, 2022
Android Patch Level:
None
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter