Possible Arbitrary Physical Memory Access Vulnerability in sm_mem_compat_get_vmm_obj
CVE-2024-47027
What is CVE-2024-47027?
A vulnerability exists in the shared memory component of Android devices, specifically in the function sm_mem_compat_get_vmm_obj located in lib/sm/shared_mem.c. This flaw is characterized by improper input validation, which may allow local attackers to gain unauthorized access to arbitrary physical memory. Exploitation does not require any additional execution privileges or user interaction, making it particularly concerning. The implications include potential privilege escalation, allowing an attacker to perform actions beyond their intended permissions, thus compromising the security and integrity of the affected devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Android Android kernel
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved