In iomatchtask of io_uring.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "severity": "High", "fixes": [ "https://android.googlesource.com/kernel/common/+/812805ff3b0c7", "https://android.googlesource.com/kernel/common/+/29f077d070519" ], "types": [ "EoP" ], "vanir_signatures": [ { "id": "ASB-A-230867044-109d8e6a", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "fs/io_uring.c" }, "digest": { "line_hashes": [ "272162681072718761223832810924314861088", "282435767030736005459484303915207870642", "77554876585778307774017004807339822970", "222188109909390957259112931253691907692" ], "threshold": 0.9 }, "source": "https://android.googlesource.com/kernel/common/+/29f077d070519" }, { "id": "ASB-A-230867044-85e9891a", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "function": "io_req_init_async", "file": "fs/io_uring.c" }, "digest": { "function_hash": "227273210715688725373639114611586646087", "length": 305.0 }, "source": "https://android.googlesource.com/kernel/common/+/29f077d070519" }, { "id": "ASB-A-230867044-f53ab9c2", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "fs/io_uring.c" }, "digest": { "line_hashes": [ "272162681072718761223832810924314861088", "282435767030736005459484303915207870642", "77554876585778307774017004807339822970", "222188109909390957259112931253691907692" ], "threshold": 0.9 }, "source": "https://android.googlesource.com/kernel/common/+/812805ff3b0c7" }, { "id": "ASB-A-230867044-fda9fe1a", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "function": "io_req_init_async", "file": "fs/io_uring.c" }, "digest": { "function_hash": "227273210715688725373639114611586646087", "length": 305.0 }, "source": "https://android.googlesource.com/kernel/common/+/812805ff3b0c7" } ], "spl": "2022-10-05" }