MEDIUM 6.7 Microsoft
CVE-2022-20454
In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242096164
Microsoft Security Update 2026-Aug: In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242096164
Affected Products
- cbl2 qemu 6.2.0-24
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-20454
- https://nvd.nist.gov/vuln/detail/CVE-2022-20454
This medium severity vulnerability with a CVSS score of 6.7 was published on 2026-08-06 via Microsoft. Affected: cbl2 qemu 6.2.0-24.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.