In ioidentitycow of io_uring.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "signature_type": "Line", "signature_version": "v1", "id": "ASB-A-238177383-1c649e06", "target": { "file": "fs/io_uring.c" }, "deprecated": false, "digest": { "line_hashes": [ "283555694453714368821874255168558772476", "134417412181918471945274425715513413757", "484510208167674657433280657768788496", "305247541390997635524119772618650777746" ], "threshold": 0.9 }, "source": "https://android.googlesource.com/kernel/common/+/0380da7fd63ac93caf96a75d1b31e388d3c754e9" }, { "signature_type": "Function", "signature_version": "v1", "id": "ASB-A-238177383-3c096081", "target": { "function": "io_identity_cow", "file": "fs/io_uring.c" }, "deprecated": false, "digest": { "length": 793.0, "function_hash": "7706770934050613843200183825408069182" }, "source": "https://android.googlesource.com/kernel/common/+/0380da7fd63ac93caf96a75d1b31e388d3c754e9" } ], "severity": "Moderate", "fixes": [ "https://android.googlesource.com/kernel/common/+/0380da7fd63ac93caf96a75d1b31e388d3c754e9" ], "types": [ "EoP" ], "spl": "2022-10-05" }