CVE-2021-0920
CVE Published | 2021-12-15 |
---|---|
Related CWE(s) | CWE-416: Use After Free, CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') |
Related Vendor(s) | debian, google |
Related Product(s) | android, debian_linux |
Exploitation Reported (CISA KEV) | 2022-05-23 |
CVSS 3 Base Score | 6.4 (MEDIUM) |
CVSS 3 Attack Complexity | HIGH |
CVSS 3 Attack Vector | LOCAL |
In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph