CVE-2022-20154
published 2022-06-15CVE-2022-20154: In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System…
PriorityP428medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
0.11%
1.3th percentile
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.15.15-1 (bookworm) | linux 5.15.15-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.10.92-1 | 5.10.92-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
| linux | linux_kernel | >= 0 < 5.15.15-1 | 5.15.15-1 |
CVSS provenance
nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: possible use after free in lock_sock_nested of sock.c for the SCTP protocol
vendor_redhat·2022-06-15·CVSS 6.4
CVE-2022-20154 [MEDIUM] kernel: possible use after free in lock_sock_nested of sock.c for the SCTP protocol
kernel: possible use after free in lock_sock_nested of sock.c for the SCTP protocol
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel
A use-after-free flaw due to a race condition was found in the Linux kernel’s sctp_diag module. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Mitigation: To mitigate this issue, prevent the sctp module from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automa
Debian
CVE-2022-20154: linux - In lock_sock_nested of sock.c, there is a possible use after free due to a race ...
vendor_debian·2022·CVSS 6.4
CVE-2022-20154 [MEDIUM] CVE-2022-20154: linux - In lock_sock_nested of sock.c, there is a possible use after free due to a race ...
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 5.15.15-1)
bullseye: resolved (fixed in 5.10.92-1)
forky: resolved (fixed in 5.15.15-1)
sid: resolved (fixed in 5.15.15-1)
trixie: resolved (fixed in 5.15.15-1)
GHSA
GHSA-894g-wr4p-3595: In lock_sock_nested of sock
ghsa_unreviewed·2022-06-16
CVE-2022-20154 [MEDIUM] CWE-362 GHSA-894g-wr4p-3595: In lock_sock_nested of sock
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel
OSV
CVE-2022-20154: In lock_sock_nested of sock
osv·2022-06-15·CVSS 6.4
CVE-2022-20154 [MEDIUM] CVE-2022-20154: In lock_sock_nested of sock
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel
OSV
CVE-2022-20154: In lock_sock_nested of sock
osv·2022-06-01
CVE-2022-20154 CVE-2022-20154: In lock_sock_nested of sock
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
No detection rules found.
No public exploits indexed.
2022-06-15
Published