In ioidentitycow of io_uring.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "283555694453714368821874255168558772476", "134417412181918471945274425715513413757", "484510208167674657433280657768788496", "305247541390997635524119772618650777746" ] }, "id": "ASB-A-238177383-1c649e06", "source": "https://android.googlesource.com/kernel/common/+/0380da7fd63ac93caf96a75d1b31e388d3c754e9", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/io_uring.c" }, "signature_type": "Line" }, { "digest": { "length": 793.0, "function_hash": "7706770934050613843200183825408069182" }, "id": "ASB-A-238177383-3c096081", "source": "https://android.googlesource.com/kernel/common/+/0380da7fd63ac93caf96a75d1b31e388d3c754e9", "deprecated": false, "signature_version": "v1", "target": { "file": "fs/io_uring.c", "function": "io_identity_cow" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/0380da7fd63ac93caf96a75d1b31e388d3c754e9" ], "spl": "2022-10-05", "severity": "Moderate", "types": [ "EoP" ] }