Candidate: CVE-2012-6422 PublicDate: 2012-12-18 00:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6422 Description: The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memory and gain privileges via a crafted application, as demonstrated by ExynosAbuse. Ubuntu-Description: Notes: jdstrand> android kernels (goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 13.10 preview kernels jdstrand> /dev/exynos-mem not used on reference devices Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_linux-goldfish: upstream_linux-goldfish: needs-triage lucid_linux-goldfish: DNE precise_linux-goldfish: DNE quantal_linux-goldfish: DNE saucy_linux-goldfish: ignored devel_linux-goldfish: ignored Patches_linux-grouper: upstream_linux-grouper: needs-triage lucid_linux-grouper: DNE precise_linux-grouper: DNE quantal_linux-grouper: DNE saucy_linux-grouper: ignored devel_linux-grouper: ignored Patches_linux-maguro: upstream_linux-maguro: needs-triage lucid_linux-maguro: DNE precise_linux-maguro: DNE quantal_linux-maguro: DNE saucy_linux-maguro: ignored devel_linux-maguro: ignored Patches_linux-mako: upstream_linux-mako: needs-triage lucid_linux-mako: DNE precise_linux-mako: DNE quantal_linux-mako: DNE saucy_linux-mako: ignored devel_linux-mako: ignored Patches_linux-manta: upstream_linux-manta: needs-triage lucid_linux-manta: DNE precise_linux-manta: DNE quantal_linux-manta: DNE saucy_linux-manta: ignored devel_linux-manta: ignored Patches_linux-flo: upstream_linux-flo: needs-triage lucid_linux-flo: DNE precise_linux-flo: DNE quantal_linux-flo: DNE saucy_linux-flo: DNE devel_linux-flo: ignored