In (TBD) of (TBD), there is a possible way to corrupt kernel memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"spl": "2022-12-05",
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"53554243285977009445241058032053674746",
"7125049686170939624856544760172891849",
"322493050432685491265115722998336088033",
"243084906520757196193095533494977015948",
"297068261339370114496024738951383122659",
"293848212678086232354619805874054528634",
"193210245299654786613574545910194724936",
"24232236702965942071285283687131851084"
]
},
"source": "https://android.googlesource.com/kernel/common/+/bc80ea8a4296c4d75f7e3e27b65718cae09f20f1",
"id": "PUB-A-220738351-04fcee34",
"deprecated": false,
"target": {
"file": "fs/io_uring.c"
},
"signature_version": "v1",
"signature_type": "Line"
},
{
"digest": {
"function_hash": "223266524461376812538607438725053161285",
"length": 397.0
},
"source": "https://android.googlesource.com/kernel/common/+/bc80ea8a4296c4d75f7e3e27b65718cae09f20f1",
"id": "PUB-A-220738351-e371351c",
"deprecated": false,
"target": {
"file": "fs/io_uring.c",
"function": "io_statx"
},
"signature_version": "v1",
"signature_type": "Function"
}
],
"severity": "Moderate",
"fixes": [
"https://android.googlesource.com/kernel/common/+/bc80ea8a4296c4d75f7e3e27b65718cae09f20f1"
],
"types": [
"EoP"
]
}