Vulnerability Name:

CVE-2022-20154 (CCN-229056)

Assigned:2021-10-14
Published:2022-06-06
Updated:2022-06-24
Summary:In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel
CVSS v3 Severity:6.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)
5.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.7 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-362
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: Google Web site
Android

Source: MITRE
Type: CNA
CVE-2022-20154

Source: XF
Type: UNKNOWN
android-cve202220154-priv-esc(229056)

Source: CCN
Type: Android Open Source Project
Pixel Update Bulletin—June 2022

Source: MISC
Type: Vendor Advisory
https://source.android.com/security/bulletin/pixel/2022-06-01

Vulnerable Configuration:Configuration 1:
  • cpe:/o:google:android:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:google:android:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8029
    P
    kernel-docs-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:8090
    P
    reiserfs-kmp-default-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7539
    P
    kernel-64kb-5.14.21-150500.53.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:118792
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:119653
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:118982
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:118235
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:119287
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:118655
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:119468
    P
    Security update for the Linux Kernel (Important)
    2022-08-15
    oval:org.opensuse.security:def:4737
    P
    Security update for the Linux Kernel (Important)
    2022-08-02
    oval:org.opensuse.security:def:3753
    P
    Security update for the Linux Kernel (Important)
    2022-08-01
    oval:org.opensuse.security:def:627
    P
    Security update for the Linux Kernel (Important)
    2022-08-01
    oval:org.opensuse.security:def:95383
    P
    Security update for the Linux Kernel (Important)
    2022-08-01
    oval:org.opensuse.security:def:598
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:42325
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:43652
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:42421
    P
    Security update for the Linux Kernel (Important)
    2022-07-26
    oval:org.opensuse.security:def:94472
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:93159
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:4653
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 12 SP5) (Important)
    2022-07-21
    oval:org.opensuse.security:def:95355
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP4) (Important)
    2022-07-21
    oval:org.opensuse.security:def:118217
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP2) (Important)
    2022-07-21
    oval:org.opensuse.security:def:93837
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:4657
    P
    Security update for the Linux Kernel (Live Patch 28 for SLE 12 SP5) (Important)
    2022-07-21
    oval:org.opensuse.security:def:125381
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 12 SP4) (Important)
    2022-07-21
    oval:org.opensuse.security:def:3720
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:4650
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 12 SP5) (Important)
    2022-07-21
    oval:org.opensuse.security:def:95427
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:118222
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP2) (Important)
    2022-07-21
    oval:org.opensuse.security:def:95273
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:93319
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:3783
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:4654
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP5) (Important)
    2022-07-21
    oval:org.opensuse.security:def:95356
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:118219
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP2) (Important)
    2022-07-21
    oval:org.opensuse.security:def:94051
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:4658
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP5) (Important)
    2022-07-21
    oval:org.opensuse.security:def:125382
    P
    Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP4) (Important)
    2022-07-21
    oval:org.opensuse.security:def:3725
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP4) (Important)
    2022-07-21
    oval:org.opensuse.security:def:4651
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 12 SP5) (Important)
    2022-07-21
    oval:org.opensuse.security:def:95335
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:118214
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 15 SP2) (Important)
    2022-07-21
    oval:org.opensuse.security:def:93477
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:3794
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:4655
    P
    Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP5) (Important)
    2022-07-21
    oval:org.opensuse.security:def:3643
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:118220
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 15 SP2) (Important)
    2022-07-21
    oval:org.opensuse.security:def:94263
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:3726
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:4652
    P
    Security update for the Linux Kernel (Live Patch 29 for SLE 12 SP5) (Important)
    2022-07-21
    oval:org.opensuse.security:def:95350
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:118215
    P
    Security update for the Linux Kernel (Live Patch 26 for SLE 15 SP2) (Important)
    2022-07-21
    oval:org.opensuse.security:def:93630
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:589
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:4656
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP5) (Important)
    2022-07-21
    oval:org.opensuse.security:def:3705
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:95416
    P
    Security update for the Linux Kernel (Important)
    2022-07-21
    oval:org.opensuse.security:def:118221
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP2) (Important)
    2022-07-21
    oval:org.opensuse.security:def:118212
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 15 SP2) (Important)
    2022-07-20
    oval:org.opensuse.security:def:118213
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 15 SP2) (Important)
    2022-07-20
    oval:org.opensuse.security:def:118210
    P
    Security update for the Linux Kernel (Live Patch 17 for SLE 15 SP2) (Important)
    2022-07-20
    oval:org.opensuse.security:def:125379
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP4) (Important)
    2022-07-20
    oval:org.opensuse.security:def:118211
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP2) (Important)
    2022-07-20
    oval:org.opensuse.security:def:125380
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 12 SP4) (Important)
    2022-07-20
    oval:org.opensuse.security:def:125377
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP4) (Important)
    2022-07-19
    oval:org.opensuse.security:def:4644
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 12 SP5) (Important)
    2022-07-19
    oval:org.opensuse.security:def:118209
    P
    Security update for the Linux Kernel (Live Patch 27 for SLE 15 SP2) (Important)
    2022-07-19
    oval:org.opensuse.security:def:125378
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP4) (Important)
    2022-07-19
    oval:org.opensuse.security:def:4645
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP5) (Important)
    2022-07-19
    oval:org.opensuse.security:def:4647
    P
    Security update for the Linux Kernel (Live Patch 30 for SLE 12 SP5) (Important)
    2022-07-19
    oval:org.opensuse.security:def:4648
    P
    Security update for the Linux Kernel (Live Patch 32 for SLE 12 SP5) (Important)
    2022-07-19
    oval:org.opensuse.security:def:43645
    P
    Security update for the Linux Kernel (Important)
    2022-07-18
    oval:org.opensuse.security:def:42412
    P
    Security update for the Linux Kernel (Important)
    2022-07-18
    oval:org.opensuse.security:def:42317
    P
    Security update for the Linux Kernel (Important)
    2022-07-18
    oval:org.opensuse.security:def:582
    P
    Security update for the Linux Kernel (Important)
    2022-07-15
    oval:org.opensuse.security:def:126919
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:127316
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:125116
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:125755
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:125375
    P
    Security update for the Linux Kernel (Important)
    2022-07-14
    oval:org.opensuse.security:def:5294
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:4300
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:6097
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:4642
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:6344
    P
    Security update for the Linux Kernel (Important)
    2022-07-13
    oval:org.opensuse.security:def:6096
    P
    Security update for the Linux Kernel (Important)
    2022-07-12
    BACK
    google android -
    google android -