In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443; Issue ID: MSV-3966.
| Software | From | Fixed in |
|---|---|---|
| linuxfoundation / yocto | 4.0 | 4.0.x |
| rdkcentral / rdk-b | 2024q1 | 2024q1.x |
| google / android | 14.0 | 14.0.x |
| google / android | 15.0 | 15.0.x |
| openwrt / openwrt | 21.02.0 | 21.02.0.x |
| openwrt / openwrt | 23.05.0 | 23.05.0.x |
| zephyrproject / zephyr | 3.7.0 | 3.7.0.x |