In virtiotransportdestruct of virtiotransportcommon.c, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"id": "ASB-A-378870958-97da122b",
"deprecated": false,
"target": {
"file": "net/vmw_vsock/virtio_transport_common.c"
},
"digest": {
"line_hashes": [
"93977310876986077576665763442512925816",
"163800357948092888600624900561682532725",
"136815264389493747422028697590892460623",
"163716186038971930399625291126554016251"
],
"threshold": 0.9
},
"source": "https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b",
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "ASB-A-378870958-f5395513",
"deprecated": false,
"target": {
"function": "virtio_transport_destruct",
"file": "net/vmw_vsock/virtio_transport_common.c"
},
"digest": {
"length": 86.0,
"function_hash": "29489074915205943468631857696750719064"
},
"source": "https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b",
"signature_version": "v1",
"signature_type": "Function"
}
],
"severity": "High",
"types": [
"EoP"
],
"spl": "2025-04-05",
"fixes": [
"https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b"
]
}