PT-2021-1504 · Google+7 · Android Kernel+7

Published

2021-07-16

·

Updated

2024-02-02

·

CVE-2022-20141

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Android kernel versions (affected versions not specified)
Description: The issue is related to the implementation of the ip check mc rcu() function in the Inet Sockets component of the Android kernel, which involves the use of memory after it has been freed due to improper locking. This could lead to local escalation of privilege when opening and closing inet sockets, with no additional execution privileges needed. User interaction is not required for exploitation.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

Improper Locking

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2148
ALSA-2023:2458
ALSA-2023:2736
ALSA-2023:2951
ALT-PU-2022-2679
ASB-A-112551163
BDU:2022-04777
CESA-2023_2736
CESA-2023_2951
CVE-2022-20141
OESA-2022-1837
OPENSUSE-SU-2022:2177-1
OPENSUSE-SU-2022:2549-1
OPENSUSE-SU-2022_2172-1
OPENSUSE-SU-2022_2411-1
OPENSUSE-SU-2022_2422-1
OPENSUSE-SU-2022_2549-1
RHSA-2023:2148
RHSA-2023:2458
RHSA-2023:2736
RHSA-2023:2951
RHSA-2023_2148
RHSA-2023_2458
RHSA-2023_2736
RHSA-2023_2951
RHSA-2024:0412
SUSE-SU-2022:2172-1
SUSE-SU-2022:2177-1
SUSE-SU-2022:2377-1
SUSE-SU-2022:2379-1
SUSE-SU-2022:2382-1
SUSE-SU-2022:2393-1
SUSE-SU-2022:2407-1
SUSE-SU-2022:2411-1
SUSE-SU-2022:2478-1
SUSE-SU-2022:2549-1
SUSE-SU-2022:2629-1
SUSE-SU-2022:2696-1
SUSE-SU-2022:2697-1
SUSE-SU-2022:2699-1
SUSE-SU-2022:2700-1
SUSE-SU-2022:2709-1
SUSE-SU-2022:2710-1
SUSE-SU-2022:2726-1
SUSE-SU-2022:2727-1
SUSE-SU-2022:2728-1
SUSE-SU-2022:2732-1
SUSE-SU-2022:2738-1
SUSE-SU-2022:2745-1
SUSE-SU-2022:2750-1
SUSE-SU-2022:2759-1
SUSE-SU-2022:2762-1
SUSE-SU-2022:2766-1
SUSE-SU-2022:2770-1
SUSE-SU-2022:2776-1
SUSE-SU-2022:2779-1
SUSE-SU-2022:2780-1
SUSE-SU-2022:2781-1
SUSE-SU-2022:2783-1
SUSE-SU-2022:2789-1
SUSE-SU-2022:2809-1
USN-5540-1

Affected Products

Alt Linux
Almalinux
Android Kernel
Astra Linux
Centos
Red Hat
Suse
Ubuntu