Description In binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-254837884References: Upstream kernel
CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Exploitability: 1.8 | Impact: 5.9 Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages4 packages
🔴 Vulnerability Details8 OSV linux-bluefield vulnerabilities ↗ 2023-03-03 ▶ OSV linux-azure-fde vulnerabilities ↗ 2023-03-02 ▶ OSV linux-aws-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-oracle-5.4 vulnerabilities ↗ 2023-02-15 ▶ OSV linux-gke vulnerabilities ↗ 2023-02-15 ▶ OSV linux, linux-aws, linux-azure, linux-azure-5.4, linux-gkeop, linux-kvm, linux-oracle, linux-raspi, linux-raspi-5.4 vulnerabilities ↗ 2023-02-09 ▶ Show 3 more
📋 Vendor Advisories6 Ubuntu Linux kernel (BlueField) vulnerabilities ↗ 2023-03-03 ▶ Ubuntu Linux kernel (Azure CVM) vulnerabilities ↗ 2023-03-02 ▶ Ubuntu Linux kernel (GKE) vulnerabilities ↗ 2023-02-15 ▶ Ubuntu Linux kernel vulnerabilities ↗ 2023-02-15 ▶ Android CVE-2023-20928: Binder driver ↗ 2023-01-01 ▶ Show 1 more