UBUNTU-CVE-2021-0935
In ip6_xmit of ip6_output.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168607263References: Upstream kernel
02 / AFFECTED SOFTWARE
Affected packages
50 explicit affected versions
6 explicit affected versions
6 explicit affected versions
191 explicit affected versions
4 explicit affected versions
23 explicit affected versions
72 explicit affected versions
1 explicit affected versions
7 explicit affected versions
12 explicit affected versions
1 explicit affected versions
138 explicit affected versions
71 explicit affected versions
4 explicit affected versions
29 explicit affected versions
13 explicit affected versions
33 explicit affected versions
10 explicit affected versions
11 explicit affected versions
2 explicit affected versions
15 explicit affected versions
15 explicit affected versions
5 explicit affected versions
10 explicit affected versions
44 explicit affected versions
16 explicit affected versions
38 explicit affected versions
9 explicit affected versions
115 explicit affected versions
34 explicit affected versions
50 explicit affected versions
4 explicit affected versions
43 explicit affected versions
93 explicit affected versions
12 explicit affected versions
4 explicit affected versions
1 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In ip6_xmit of ip6_output.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168607263References: Upstream kernel
05 / REFERENCES
Further evidence
- https://git.kernel.org/linus/2f987a76a97773beafbc615b9c4d8fe79129a7f4
- https://git.kernel.org/linus/b954f94023dcc61388c8384f0f14eb8e42c863c5
- https://groups.google.com/g/syzkaller-bugs/c/N53POqzMUa0/m/bTV9futJBAAJ
- https://source.android.com/security/bulletin/pixel/2021-10-01
- https://ubuntu.com/security/CVE-2021-0935
- https://ubuntu.com/security/notices/USN-5361-1
- https://www.cve.org/CVERecord?id=CVE-2021-0935