Vulnerability Name:

CVE-2022-20141 (CCN-228896)

Assigned:2021-10-14
Published:2022-06-07
Updated:2022-09-01
Summary:In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege when opening and closing inet sockets with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-112551163References: Upstream kernel
CVSS v3 Severity:7.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.1 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
7.3 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-362
CWE-667
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: Google Web site
Android

Source: MITRE
Type: CNA
CVE-2022-20141

Source: XF
Type: UNKNOWN
android-cve202220141-priv-esc(228896)

Source: CCN
Type: Android Open Source Project
Android Security Bulletin - June 2022

Source: MISC
Type: Vendor Advisory
https://source.android.com/security/bulletin/2022-06-01

Vulnerable Configuration:Configuration 1:
  • cpe:/o:google:android:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:google:android:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:118982
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:118235
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:119287
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:118655
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:119468
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:118792
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:119653
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:4674
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP5) (Important)
    2022-08-11
    oval:org.opensuse.security:def:118232
    P
    Security update for the Linux Kernel (Live Patch 26 for SLE 15 SP2) (Important)
    2022-08-11
    oval:org.opensuse.security:def:4675
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 12 SP5) (Important)
    2022-08-11
    oval:org.opensuse.security:def:118233
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 15 SP2) (Important)
    2022-08-11
    oval:org.opensuse.security:def:4676
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 12 SP5) (Important)
    2022-08-11
    oval:org.opensuse.security:def:4673
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP5) (Important)
    2022-08-11
    oval:org.opensuse.security:def:118234
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP2) (Important)
    2022-08-11
    oval:org.opensuse.security:def:4670
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118231
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4667
    P
    Security update for the Linux Kernel (Live Patch 29 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118228
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4671
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118225
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4668
    P
    Security update for the Linux Kernel (Live Patch 28 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118229
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4672
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118226
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4669
    P
    Security update for the Linux Kernel (Live Patch 30 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118230
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:4666
    P
    Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP5) (Important)
    2022-08-10
    oval:org.opensuse.security:def:118227
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 15 SP2) (Important)
    2022-08-10
    oval:org.opensuse.security:def:125385
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP4) (Important)
    2022-08-09
    oval:org.opensuse.security:def:125386
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP4) (Important)
    2022-08-09
    oval:org.opensuse.security:def:125387
    P
    Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP4) (Important)
    2022-08-09
    oval:org.opensuse.security:def:125384
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 12 SP4) (Important)
    2022-08-08
    oval:org.opensuse.security:def:125383
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP4) (Important)
    2022-08-08
    oval:org.opensuse.security:def:4737
    P
    Security update for the Linux Kernel (Important)
    2022-08-02
    oval:org.opensuse.security:def:42421
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:598
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:42325
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:43652
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:582
    P
    Security update for the Linux Kernel (Important)
    2022-07-15
    oval:org.opensuse.security:def:125755
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:125116
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:126919
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:125375
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:127316
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:6344
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:5294
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:4300
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:4642
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:6097
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:6096
    P
    Security update for the Linux Kernel (Important)
    2022-07-12
    oval:org.opensuse.security:def:1562
    P
    Security update for the Linux Kernel (Important)
    2022-06-24
    oval:org.opensuse.security:def:42304
    P
    Security update for the Linux Kernel (Important)
    2022-06-24
    oval:org.opensuse.security:def:1597
    P
    Security update for the Linux Kernel (Important)
    2022-06-24
    oval:org.opensuse.security:def:43636
    P
    Security update for the Linux Kernel (Important)
    2022-06-24
    oval:org.opensuse.security:def:42400
    P
    Security update for the Linux Kernel (Important)
    2022-06-24
    BACK
    google android -
    google android -