CVE-2022-20422Improper Locking in Google Android

Severity
7.0HIGHNVD
EPSS
0.0%
top 86.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateApr 13

Description

In emulation_proc_handler of armv8_deprecated.c, there is a possible way to corrupt memory due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-237540956References: Upstream kernel

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages4 packages

Debianlinux/linux_kernel< 5.10.140-1+3
Ubuntulinux/linux_kernel< 4.15.0-197.208+3
debiandebian/linux< linux 5.19.6-1 (bookworm)

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

14
VulDB
Google Android armv8_deprecated.c emulation_proc_handler race condition (A-237540956 / EUVD-2022-25682)2026-04-13
VulDB
Google Android race condition (A-237540956 / EUVD-2022-25682)2026-04-13
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2024-04-19
OSV
linux-azure vulnerabilities2022-12-12
OSV
linux-gcp-5.4 vulnerabilities2022-11-29

📋Vendor Advisories

13
Ubuntu
Linux kernel vulnerabilities2024-04-19
CISA ICS
Siemens SIMATIC2024-03-14
CISA ICS
Siemens SIMATIC S7-1500 TM MFP BIOS2023-06-15
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel2023-06-15
Ubuntu
Linux kernel (Azure) vulnerabilities2022-12-12