Out-of-bounds write in Google Android - CVE-2020-0022
Published: February 14, 2020 / Updated: September 13, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists within the System functionality of Android due to a boundary error when processing untrusted input in "reassemble_and_dispatch" of "packet_fragmenter.cc". A remote attacker can trigger out-of-bounds write and execute arbitrary code over Bluetooth on the target system.
Affected software
Huawei Mate 20 Pro
Huawei Mate 20 X
Huawei P20
Huawei P20 Pro
Huawei P30
Huawei P30 Pro
Huawei nova 3e
Huawei Mate 20
How to mitigate CVE-2020-0022
Huawei Mate 20 X - update to 10.0.0.195
Huawei P20 - update to 10.0.0.162
Huawei P20 Pro - update to 10.0.0.162
Huawei P30 - addressed in versions 10.0.0.190, 10.0.0.195
Huawei P30 Pro - update to 10.0.0.195
Huawei nova 3e - update to 9.1.0.338
Huawei Mate 20 - update to 10.0.0.195
Links to Public Exploits and PoC-codes
- Exploit #9322 - CVE-2020-0022 (A fully public exploit of the CVE-2020-0022 BlueFrag Android RCE Vulnerability (tested on Pixel 3 XL)) (September 13, 2023)
- Exploit #6983 - poc-for-cve-2020-0022 (cve-2020-0022) (November 3, 2021)
- Exploit #6563 - Bluefrag_CVE-2020-0022 (This is a RCE bluetooth vulnerability on Android 8.0 and 9.0) (July 25, 2021)
- Exploit #5176 - CVE-2020-0022 () (February 25, 2021)
- Exploit #4936 - cve-2020-0022 (cve-2020-0022相关的一些东西) (December 16, 2020)
- Exploit #4523 - CVE-2020-0022 (CVE-2020-0022 vulnerability exploitation on Bouygues BBox Miami (Android TV 8.0 - ARM32 Cortex A9)) (September 1, 2020)
- Exploit #2976 - CVE-2020-0022 (BlueFrag experiments) (June 3, 2020)
- Exploit #2847 - cve-2020-0022 (poc for cve-2020-0022) (June 3, 2020)