In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"fixes": [
"https://android.googlesource.com/kernel/common/+/bc80ea8a4296c4d75f7e3e27b65718cae09f20f1"
],
"severity": "Moderate",
"types": [
"EoP"
],
"spl": "2022-12-05",
"vanir_signatures": [
{
"signature_type": "Line",
"deprecated": false,
"source": "https://android.googlesource.com/kernel/common/+/bc80ea8a4296c4d75f7e3e27b65718cae09f20f1",
"digest": {
"line_hashes": [
"53554243285977009445241058032053674746",
"7125049686170939624856544760172891849",
"322493050432685491265115722998336088033",
"243084906520757196193095533494977015948",
"297068261339370114496024738951383122659",
"293848212678086232354619805874054528634",
"193210245299654786613574545910194724936",
"24232236702965942071285283687131851084"
],
"threshold": 0.9
},
"id": "PUB-A-220738351-04fcee34",
"signature_version": "v1",
"target": {
"file": "fs/io_uring.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"source": "https://android.googlesource.com/kernel/common/+/bc80ea8a4296c4d75f7e3e27b65718cae09f20f1",
"digest": {
"length": 397.0,
"function_hash": "223266524461376812538607438725053161285"
},
"id": "PUB-A-220738351-e371351c",
"signature_version": "v1",
"target": {
"function": "io_statx",
"file": "fs/io_uring.c"
}
}
]
}