

The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service (vma list corruption) via a crafted application, aka internal bug 20017123. The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875. The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before allows attackers to gain privileges via a crafted application, aka internal bug 24673908. The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before allows attackers to gain privileges via a crafted application, aka internal bug 25307013.

Mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bugs 2507046670. Please note that some of the information in the bulletin is compiled from external, open-source reports and is not a direct result of CISA analysis. Patch information is provided when available. This information may include identifying information, values, definitions, and related links.

