CVE-2024-31311 Information

Description

In increment_annotation_count of stats_event.c there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Reference

https://android.googlesource.com/platform/packages/modules/StatsD/+/b6aab6c000ab85f4e4d8bb3941bcc33800550374 https://source.android.com/security/bulletin/2024-06-01

Share on: