Back

MEDIUM

kernel: possible use after free in lock_sock_nested of sock.c for the SCTP protocol

Published Jun 15, 2022

Description

In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, prevent the sctp module from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Jun 15, 2022
Updated Aug 3, 2024
Reserved Oct 14, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 15, 2022
ENISA EUVD
Assigner google_android
Published Jun 15, 2022
Updated Aug 3, 2024
Exploited since n/a
EUVD-2022-25414