Google patches include patches up to Android Security Bulletin — March package. Some of the SVE items may not be included in this package, in case these items were already included in a previous maintenance release. A possible heap overflow vulnerability in kernel driver allows arbitrary code execution. The patch adds the proper validation of the buffer length.

Samsung Galaxy A20

A vulnerability in Lockdown mode allows exposure of notifications when pin entry limit is exceeded. The patch addressed notification exposure in Lockdown mode. An improper verification logic in touch screen firmware update process allows an attacker to load malicious firmware. The patch adds the proper validation logic in firmware update process. A vulnerability in Lockscreen of DeX allows access to quick panel and notifications without authentication.

The patch prevents access to quick panel and notifications in Lockscreen of DeX. Google patches include patches up to Android Security Bulletin — February package. Notification contents are shown on the lock screen via Routines. While it is working as intended, the patch adds detailed explanation of how notification works in Routines. A possible buffer overflow vulnerability in baseband allows arbitrary code execution. The patch adds proper boundary check to prevent buffer overflow. A vulnerability caused by missing checks of memory address accessin Widevine trustlet allows arbitrary memory read and write from non-secure memory.

The patch adds proper range check of accessible memory.

Samsung Galaxy A20

A possible stack overflow vulnerability in Esecomm trustlet allows arbitrary code execution. The patch addressed the issue.

A possible arbitrary memory write vulnerability exists in RKP. A kernel pointer leak vulnerability exists in vipx driver. The patch restricts triggering of vipx driver.

A possible arbitrary kfree vulnerability exists in vipx and vertex driver. The patch restricts triggering of vipx and vertex driver. A possible heap OOB write vulnerability exists in tsmux driver. The patch adds proper boundary check in tsmux driver. A possible race condition vulnerability exists in hdcp2 driver. The patch fixes incorrect implementation of hdcp2 driver to address race condition vulnerability. A possible OOB read vulnerability exists in media.

The patch adds the proper validation of the input value. A vulnerability caused by missing synchronization in MTP handler allows use-after-free via race condition.