In virtiotransportdestruct of virtiotransportcommon.c, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"fixes": [
"https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b"
],
"types": [
"EoP"
],
"severity": "High",
"vanir_signatures": [
{
"id": "ASB-A-378870958-97da122b",
"target": {
"file": "net/vmw_vsock/virtio_transport_common.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"93977310876986077576665763442512925816",
"163800357948092888600624900561682532725",
"136815264389493747422028697590892460623",
"163716186038971930399625291126554016251"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b",
"signature_version": "v1"
},
{
"id": "ASB-A-378870958-f5395513",
"target": {
"file": "net/vmw_vsock/virtio_transport_common.c",
"function": "virtio_transport_destruct"
},
"digest": {
"function_hash": "29489074915205943468631857696750719064",
"length": 86.0
},
"deprecated": false,
"signature_type": "Function",
"source": "https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b",
"signature_version": "v1"
}
],
"spl": "2025-04-05"
}