In virtiotransportdestruct of virtiotransportcommon.c, there is possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{ "types": [ "EoP" ], "severity": "High", "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "93977310876986077576665763442512925816", "163800357948092888600624900561682532725", "136815264389493747422028697590892460623", "163716186038971930399625291126554016251" ] }, "id": "ASB-A-378870958-97da122b", "source": "https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b", "deprecated": false, "signature_version": "v1", "signature_type": "Line", "target": { "file": "net/vmw_vsock/virtio_transport_common.c" } }, { "digest": { "function_hash": "29489074915205943468631857696750719064", "length": 86.0 }, "id": "ASB-A-378870958-f5395513", "source": "https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b", "deprecated": false, "signature_version": "v1", "signature_type": "Function", "target": { "file": "net/vmw_vsock/virtio_transport_common.c", "function": "virtio_transport_destruct" } } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/23dafd0055ada5f95360c0724f84f6e999d5407b" ], "spl": "2025-04-05" }