vulnerability
Red Hat: CVE-2022-20141: kernel: igmp: use-after-free in ip_check_mc_rcu when opening and closing inet sockets (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:M/Au:N/C:C/I:C/A:C) | Jun 15, 2022 | May 15, 2023 | Jun 17, 2026 |
Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
Jun 15, 2022
Added
May 15, 2023
Modified
Jun 17, 2026
Description
In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege when opening and closing inet sockets with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-112551163References: Upstream kernel
Solutions
redhat-upgrade-kernelredhat-upgrade-kernel-rt
References
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.