CVE-2023-20938
In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257685302References: Upstream kernel
02 / AFFECTED SOFTWARE
Affected packages
1 explicit affected versions
04 / EVIDENCE
Source records
In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257685302References: Upstream kernel
05 / REFERENCES
Further evidence
- https://android.googlesource.com/kernel/common/+/3d213a626d2d
- https://android.googlesource.com/kernel/common/+/9d1efccf5ec3
- https://android.googlesource.com/kernel/common/+/aaf236971732
- https://android.googlesource.com/kernel/common/+/b83173bf86a9
- https://android.googlesource.com/kernel/common/+/baa23246e93f
- https://android.googlesource.com/kernel/common/+/ecf61e4e1117
- https://source.android.com/security/bulletin/2023-02-01