In iomatchtask of io_uring.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "272162681072718761223832810924314861088", "282435767030736005459484303915207870642", "77554876585778307774017004807339822970", "222188109909390957259112931253691907692" ] }, "id": "ASB-A-230867044-109d8e6a", "source": "https://android.googlesource.com/kernel/common/+/29f077d070519", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/io_uring.c" }, "signature_type": "Line" }, { "digest": { "length": 305.0, "function_hash": "227273210715688725373639114611586646087" }, "id": "ASB-A-230867044-85e9891a", "source": "https://android.googlesource.com/kernel/common/+/29f077d070519", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/io_uring.c", "function": "io_req_init_async" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "272162681072718761223832810924314861088", "282435767030736005459484303915207870642", "77554876585778307774017004807339822970", "222188109909390957259112931253691907692" ] }, "id": "ASB-A-230867044-f53ab9c2", "source": "https://android.googlesource.com/kernel/common/+/812805ff3b0c7", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/io_uring.c" }, "signature_type": "Line" }, { "digest": { "length": 305.0, "function_hash": "227273210715688725373639114611586646087" }, "id": "ASB-A-230867044-fda9fe1a", "source": "https://android.googlesource.com/kernel/common/+/812805ff3b0c7", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/io_uring.c", "function": "io_req_init_async" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/812805ff3b0c7", "https://android.googlesource.com/kernel/common/+/29f077d070519" ], "spl": "2022-10-05", "severity": "High", "types": [ "EoP" ] }