In rcucblistdequeue of rcu_segcblist.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
{
"fixes": [
"https://android.googlesource.com/kernel/common/+/6282531a84bc3",
"https://android.googlesource.com/kernel/common/+/dc1163203ae6e"
],
"types": [
"EoP"
],
"severity": "Moderate",
"vanir_signatures": [
{
"id": "PUB-A-222091980-512697e0",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"14713863431515729283607372915929630473",
"73721988287512903752427978084083039489",
"206909965113241066935273885927730003046",
"238595084612937447669323305018404261028",
"207894611227891877965351819903425392602",
"120016117689637547751196975801191554412",
"301513604406674256045888246483829841860",
"62691881503194734638689328900835486157",
"51719722729921951407857325737768469856",
"58793450764127675124985092392227439445",
"173961660483178166494998022307965583271",
"228494980629219531657304145626732197226",
"262895292314214123638568828246434456673",
"214267295237758998542671140768996661711"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://android.googlesource.com/kernel/common/+/dc1163203ae6e",
"target": {
"file": "fs/io_uring.c"
}
},
{
"id": "PUB-A-222091980-a6b4a35a",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"14713863431515729283607372915929630473",
"73721988287512903752427978084083039489",
"206909965113241066935273885927730003046",
"238595084612937447669323305018404261028",
"207894611227891877965351819903425392602",
"120016117689637547751196975801191554412",
"301513604406674256045888246483829841860",
"62691881503194734638689328900835486157",
"51719722729921951407857325737768469856",
"58793450764127675124985092392227439445",
"173961660483178166494998022307965583271",
"228494980629219531657304145626732197226",
"262895292314214123638568828246434456673",
"214267295237758998542671140768996661711"
]
},
"deprecated": false,
"signature_type": "Line",
"source": "https://android.googlesource.com/kernel/common/+/6282531a84bc3",
"target": {
"file": "fs/io_uring.c"
}
}
],
"spl": "2022-06-05"
}