PT-2021-7644 · Google+1 · Android Kernel+1

Published

2021-11-06

·

Updated

2022-08-13

·

CVE-2022-20158

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version Android kernel
Description The issue is related to a memory corruption vulnerability in the backing-dev.c file of the Linux operating system, specifically in the bdi put() and bdi unregister() functions. This vulnerability is due to the use of previously freed memory, which could allow an attacker to cause a denial of service. The vulnerability could also lead to local escalation of privilege with system execution privileges needed, and user interaction is not required for exploitation.
Recommendations For Linux kernel versions prior to the fixed version: update to a version that includes the fix for this issue. For Android kernel: apply the patch from the upstream kernel to resolve the issue. As a temporary workaround, consider restricting access to the bdi put() and bdi unregister() functions until a patch is available.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2023-00745
CVE-2022-20158

Affected Products

Android Kernel
Linux Kernel