CVE-2025-36935
🟡 Monitoruj
Korupcja pamięci w trusty_ffa_mem_reclaim umożliwia lokalną eskalację uprawnień.
CVSS
7.8
EPSS
0.1%
Exploit
none
Vendor
google
Opis źródłowy (NVD)
In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2025-12-11 20:15:58 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 16:10:00 UTC |
Referencje
- https://source.android.com/security/bulletin/pixel/2025-12-01 ([email protected]) [Vendor Advisory]