PT-2021-1504 · Google+7 · Android Kernel+7
CVE-2022-20141
·
Published
2021-07-16
·
Updated
2024-02-02
CVSS v4.0
7.3
High
| Vector | AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Android kernel versions (affected versions not specified)
Description:
The issue is related to the implementation of the
ip check mc rcu() function in the Inet Sockets component of the Android kernel, which involves the use of memory after it has been freed due to improper locking. This could lead to local escalation of privilege when opening and closing inet sockets, with no additional execution privileges needed. User interaction is not required for exploitation.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Use After Free
Improper Locking
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Android Kernel
Astra Linux
Centos
Red Hat
Suse
Ubuntu