CVE-2022-20568
published 2022-12-16CVE-2022-20568: In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.1th percentile
In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-220738351References: Upstream kernel
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.14.6-1 (bookworm) | linux 5.14.6-1 (bookworm) |
| linux | linux_kernel | >= 0 < 5.10.120-1 | 5.10.120-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
| linux | linux_kernel | >= 0 < 5.14.6-1 | 5.14.6-1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Android Kernel use after free (A-220738351 / EUVD-2022-25828)
vuldb·2026-04-22·CVSS 7.8
CVE-2022-20568 [HIGH] Google Android Kernel use after free (A-220738351 / EUVD-2022-25828)
A vulnerability classified as critical has been found in Google Android. The impacted element is an unknown function of the component Kernel. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2022-20568. Local access is required to approach this attack. No exploit exists.
It is recommended to apply a patch to fix this issue.
GHSA
GHSA-3432-qjmc-vp87: In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free
ghsa_unreviewed·2022-12-21
CVE-2022-20568 [HIGH] CWE-416 GHSA-3432-qjmc-vp87: In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free
In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-220738351References: Upstream kernel
OSV
CVE-2022-20568: In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free
osv·2022-12-16·CVSS 7.8
CVE-2022-20568 [HIGH] CVE-2022-20568: In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free
In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-220738351References: Upstream kernel
OSV
CVE-2022-20568: In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free
osv·2022-12-01
CVE-2022-20568 CVE-2022-20568: In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free
In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Debian
CVE-2022-20568: linux - In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use...
vendor_debian·2022·CVSS 7.8
CVE-2022-20568 [HIGH] CVE-2022-20568: linux - In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use...
In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-220738351References: Upstream kernel
Scope: local
bookworm: resolved (fixed in 5.14.6-1)
bullseye: resolved (fixed in 5.10.120-1)
forky: resolved (fixed in 5.14.6-1)
sid: resolved (fixed in 5.14.6-1)
trixie: resolved (fixed in 5.14.6-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-16
Published