Back

MEDIUM

gdisk: possible out-of-bounds-write in LoadPartitionTable of gpt.cc

Published Aug 11, 2020

Description

In LoadPartitionTable of gpt.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege when inserting a malicious USB device, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-8.0Android ID: A-152874864

Affected products

Remediation

Red Hat statement

This vulnerability does affect Red Hat Enterprise Linux 6, 7, and 8 because our code-base is vulnerable to this issue. Red Hat Product Security has rated this issue as a Moderate security impact and the issue is not currently planned to be addressed in future updates for Red Hat Enterprise Linux 6 and 7, hence, marked as Out-of-Support-Scope. For additional information, refer to the Red Hat Enterprise Linux Life Cycle & Update Policy: https://access.redhat.com/support/policy/updates/errata/.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Aug 11, 2020
Updated Aug 4, 2024
Reserved Oct 17, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 4, 2022
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a