Back

MEDIUM

kernel: use after free in tun_get_user of tun.c could lead to local escalation of privilege

Published Jan 11, 2021

Description

In tun_get_user of tun.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges required. User interaction is not required for exploitation. Product: Android; Versions: Android kernel; Android ID: A-146554327.

Affected products

Remediation

Red Hat statement

This flaw is rated as having Moderate impact because of the need to have elevated privileges and non-standard configuration of the networking device.

Red Hat mitigation

To mitigate this issue, prevent the module tun from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Jan 11, 2021
Updated Aug 3, 2024
Reserved Nov 6, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 11, 2021