ZeroHour

CVE-2022-20141

CVSS 3.1
7.0 high
EPSS
<1%p4
Published
()
Modified
Description

In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege when opening and closing inet sockets with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-112551163References: Upstream kernel

Vendors
google
Products
android
Weakness
CWE-362, CWE-416, CWE-667
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.