PT-2021-1525 · Google+1 · Android Kernel+1

Published

2021-02-21

·

Updated

2023-08-06

·

CVE-2022-20409

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to a use after free in the io uring subsystem of the Linux kernel, which could lead to local escalation of privilege with System execution privileges needed. User interaction is not required for exploitation. This could impact the confidentiality, integrity, and availability of protected information or allow an attacker to elevate their privileges.
Recommendations For Android kernel, consider applying a patch from the upstream kernel to resolve the issue. As a temporary workaround, consider restricting access to the io uring subsystem until a patch is available. Avoid using the io identity cow function in the affected io uring.c file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ASB-A-238177383
BDU:2024-03762
CVE-2022-20409
OESA-2022-2033

Affected Products

Android Kernel
Astra Linux