In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174049066References: Upstream kernel
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Dec 15, 2021 |
| Huawei Euleros 2_0_sp10 | — | Upgrade kernel-abi-stablelistsUpgrade kernel-tools-libsUpgrade kernelUpgrade kernel-toolsUpgrade python3-perf | Apr 20, 2022 | Dec 15, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade kernel-tools-libsUpgrade kernel-toolsUpgrade kernelUpgrade python3-perf | Mar 3, 2022 | Dec 15, 2021 |
| Ubuntu | — | Upgrade linux-kvmUpgrade linux-raspiUpgrade linux-snapdragonUpgrade linux-gkeUpgrade linux-aws-hweUpgrade linux-aws-5.4Upgrade linux-raspi-5.4Upgrade linux-gkeop-5.4Upgrade linux-azure-fdeUpgrade linux-oem-5.10Upgrade linux-azureUpgrade linux-gke-5.4Upgrade linux-oracle-5.4Upgrade linux-gcp-4.15Upgrade linux-gcp-fipsUpgrade linux-gcp-5.4Upgrade linux-raspi2Upgrade linux-gcpUpgrade linux-azure-fipsUpgrade linux-azure-4.15Upgrade linux-gkeopUpgrade linux-hweUpgrade linuxUpgrade linux-aws-fipsUpgrade linux-dell300xUpgrade linux-azure-5.4Upgrade linux-hwe-5.4Upgrade linux-awsUpgrade linux-fipsUpgrade linux-oracle | Nov 19, 2024 | Dec 15, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 15, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub