In virtiotransportdestruct of virtiotransportcommon.c, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "93977310876986077576665763442512925816", "163800357948092888600624900561682532725", "136815264389493747422028697590892460623", "163716186038971930399625291126554016251" ] }, "id": "ASB-A-378870958-97da122b", "source": "https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b", "deprecated": false, "signature_version": "v1", "target": { "file": "net/vmw_vsock/virtio_transport_common.c" }, "signature_type": "Line" }, { "digest": { "length": 86.0, "function_hash": "29489074915205943468631857696750719064" }, "id": "ASB-A-378870958-f5395513", "source": "https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b", "deprecated": false, "signature_version": "v1", "target": { "file": "net/vmw_vsock/virtio_transport_common.c", "function": "virtio_transport_destruct" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b" ], "spl": "2025-04-05", "severity": "High", "types": [ "EoP" ] }