[ASB-A-233078742] Android Security - [EMBARGO 5/24] invalid-free in io_uring that can lead to LPE

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

In io_req_init_async there is a potential use after free due to a race condition. This could lead to local escalation of privileges with User execution privileges needed. User interaction is not needed for exploitation.

Package Affected Version
pkg:generic/android#linux_kernel >= :0, < :2022-08-05
Package Fixed Version
pkg:generic/android#linux_kernel = :2022-08-05
ID
ASB-A-233078742
Severity
high
URL
https://source.android.com/security/bulletin/2022-08-01
Published
2022-08-01T00:00:00
(2 years ago)
Modified
2024-07-31T14:54:59
(7 weeks ago)
Rights
Android Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:generic/android#linux_kernel android = :2022-08-05
Affected pkg:generic/android#linux_kernel android >= :0 < :2022-08-05
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...