CERT-In Vulnerability Note
CIVN-2023-0002
Multiple Vulnerabilities in Android OS
Original Issue Date:January 05, 2023
Severity Rating: CRITICAL
Software Affected
- Android versions 10, 11, 12, 12L, 13
Overview
Multiple Vulnerabilities have been reported in Android OS which could be exploited by an attacker to execute arbitrary code, gain elevated privileges and can cause denial of service condition on the targeted system.
Description
These vulnerabilities exist in Android OS due to flaws in Framework, System, Google Play system updates, Kernel, Kernel components, Kernel LTS, Imagination Technologies, MediaTek components, Unisoc components, Qualcomm components and Qualcomm closed-source components.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, gain elevated privileges and can cause denial of service condition on the targeted system.
Solution
Apply appropriate updates when made available by the respective OEMs:
https://source.android.com/docs/security/bulletin/2023-01-01
Vendor Information
Android
https://source.android.com/docs/security/bulletin/2023-01-01
References
Android
https://source.android.com/docs/security/bulletin/2023-01-01
CVE Name
CVE-2021-35097
CVE-2021-35113
CVE-2021-35134
CVE-2022-20235
CVE-2022-20456
CVE-2022-20461
CVE-2022-20489
CVE-2022-20490
CVE-2022-20492
CVE-2022-20493
CVE-2022-20494
CVE-2022-22088
CVE-2022-23960
CVE-2022-25746
CVE-2022-2959
CVE-2022-32635
CVE-2022-32636
CVE-2022-32637
CVE-2022-33252
CVE-2022-33253
CVE-2022-33255
CVE-2022-33266
CVE-2022-33274
CVE-2022-33276
CVE-2022-33283
CVE-2022-33284
CVE-2022-33285
CVE-2022-33286
CVE-2022-41674
CVE-2022-42719
CVE-2022-42720
CVE-2022-42721
CVE-2022-44425
CVE-2022-44426
CVE-2022-44427
CVE-2022-44428
CVE-2022-44429
CVE-2022-44430
CVE-2022-44431
CVE-2022-44432
CVE-2022-44434
CVE-2022-44435
CVE-2022-44436
CVE-2022-44437
CVE-2022-44438
CVE-2023-20904
CVE-2023-20905
CVE-2023-20908
CVE-2023-20912
CVE-2023-20913
CVE-2023-20915
CVE-2023-20916
CVE-2023-20918
CVE-2023-20919
CVE-2023-20920
CVE-2023-20921
CVE-2023-20922
CVE-2023-20928
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|