PT-2022-1385 · Google+2 · Android Kernel+2

Published

2022-04-22

·

Updated

2025-09-25

·

CVE-2023-20938

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue is related to a possible use after free due to improper input validation in the binder transaction buffer release of binder.c. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. The vulnerability is also related to incorrect handling of objects of type BINDER TYPE FDA of zero size.
Recommendations For Android kernel, consider disabling the vulnerable function until a patch is available. Restrict access to the binder module to minimize the risk of exploitation. Avoid using the BINDER TYPE FDA object in the affected binder.c until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-257685302
BDU:2023-00750
CVE-2023-20938
OESA-2023-1173
OESA-2023-1174
OESA-2023-1177
OESA-2023-1178
USN-5917-1
USN-5934-1
USN-5939-1
USN-5940-1
USN-5951-1
USN-6000-1
USN-6080-1
USN-6085-1
USN-6090-1
USN-6133-1
USN-6134-1

Affected Products

Android Kernel
Linuxmint
Ubuntu