Loading HuntDB...

GHSA-pwg3-f8g7-h57r

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android SoCAndroid ID: A-238379819

Related CVEs

Key Information

GHSA ID
GHSA-pwg3-f8g7-h57r
Published
September 14, 2022 12:00 AM
Last Modified
September 17, 2022 12:00 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 30, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.