CVE-2022-20141

In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege when opening and closing inet sockets with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-112551163References: Upstream kernel
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

History

01 Sep 2022, 18:58

Type Values Removed Values Added
CVSS v2 : 7.2
v3 : 7.8
v2 : 6.9
v3 : 7.0
CWE CWE-362

23 Jun 2022, 20:21

Type Values Removed Values Added
CWE CWE-667
References (MISC) https://source.android.com/security/bulletin/2022-06-01 - (MISC) https://source.android.com/security/bulletin/2022-06-01 - Vendor Advisory
CPE cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8

15 Jun 2022, 15:21

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-15 14:15

Updated : 2024-02-02 16:50


NVD link : CVE-2022-20141

Mitre link : CVE-2022-20141

CVE.ORG link : CVE-2022-20141


JSON object : View

Products Affected

google

  • android
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-416

Use After Free

CWE-667

Improper Locking