PT-2021-7644 · Google+1 · Android Kernel+1
Published
2021-11-06
·
Updated
2022-08-13
·
CVE-2022-20158
CVSS v2.0
6.8
Medium
| Vector | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to the fixed version
Android kernel
Description
The issue is related to a memory corruption vulnerability in the
backing-dev.c file of the Linux operating system, specifically in the bdi put() and bdi unregister() functions. This vulnerability is due to the use of previously freed memory, which could allow an attacker to cause a denial of service. The vulnerability could also lead to local escalation of privilege with system execution privileges needed, and user interaction is not required for exploitation.Recommendations
For Linux kernel versions prior to the fixed version: update to a version that includes the fix for this issue.
For Android kernel: apply the patch from the upstream kernel to resolve the issue.
As a temporary workaround, consider restricting access to the
bdi put() and bdi unregister() functions until a patch is available.Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Kernel
Linux Kernel