CVE-2022-20162

Publication date 15 June 2022

Last updated 1 August 2025


Ubuntu priority

Cvss 3 Severity Score

4.4 · Medium

Score breakdown

In asn1_p256_int of crypto/asn1.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-223492713References: N/A

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status

Notes


ebarretto

linux kernel for Android only.

Severity score breakdown

Parameter Value
Base score 4.4 · Medium
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N