cbcvebase.
CVE-2022-20421
published 2022-10-11

CVE-2022-20421: In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.65%
46.8th percentile
In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239630375References: Upstream kernel

Affected

11 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.19.11-1 (bookworm)linux 5.19.11-1 (bookworm)
googleandroid
linuxlinux_kernel>= 0 < 5.10.149-15.10.149-1
linuxlinux_kernel>= 0 < 5.19.11-15.19.11-1
linuxlinux_kernel>= 0 < 5.19.11-15.19.11-1
linuxlinux_kernel>= 0 < 5.19.11-15.19.11-1
linuxlinux_kernel>= 0 < 4.15.0-201.2124.15.0-201.212
linuxlinux_kernel>= 0 < 5.4.0-136.1535.4.0-136.153
linuxlinux_kernel>= 0 < 5.15.0-57.635.15.0-57.63

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.