In update_gps_sv and output_vzw_debug of vendor...
Moderate severity
Unreviewed
Published
Dec 6, 2024
to the GitHub Advisory Database
•
Updated Dec 6, 2024
Description
Published by the National Vulnerability Database
Dec 5, 2024
Published to the GitHub Advisory Database
Dec 6, 2024
Last updated
Dec 6, 2024
In update_gps_sv and output_vzw_debug of
vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/gpshal_wor
ker.c, there is a possible out of bounds write due to a missing bounds
check. This could lead to local escalation of privilege with System
execution privileges needed. User interaction is not needed for
exploitation.
References