PT-2023-17846 · Google · Android Kernel
Published
2023-03-24
·
Updated
2025-02-21
·
CVE-2023-21055
CVSS v3.1
6.4
Medium
| Vector | AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android kernel
Description
The issue is related to a possible use after free due to a race condition in the
dit hal ioctl function of dit.c. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Recommendations
For Android kernel, consider applying a patch or fix that addresses the use after free issue in the
dit hal ioctl function to prevent local escalation of privilege. As a temporary workaround, restricting access to the dit hal ioctl function may help minimize the risk of exploitation.Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Kernel