Out-of-bounds read in Google Android - CVE-2020-11125
Published: October 9, 2020
Google Android
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in the mhi_process_data_event_ring() function in drivers/bus/mhi/core/mhi_main.c file within the Qualcomm MHI bus driver. A remote attacker can trigger out-of-bounds read error and read contents of memory on the system.
Affected components: msm kernel 4.9 and msm kernel 4.14.