Junglewise Threat Intelligence

CVE-2021-0920: Android Kernel Race Condition Vulnerability

CVE-2021-0920 · Severity: critical · CVSS 6.4 · Exploited in the wild · Published 2022-05-23

Technologies: Debian Linux, Google Android, Linux Kernel. Vendors: Debian, Google, Linux.

Executive brief

A race condition in the unix_scm_to_skb function of af_unix.c in the Linux kernel leads to a use-after-free vulnerability. This flaw allows a local attacker with System execution privileges to escalate their privileges on Android devices.

Affected products

  • Google Android Kernel up to 5.13
  • Google Android
  • Debian Debian Linux 9.0

Timeline

  • 2021-11-01: advisory: Android Security Bulletin published
  • 2021-12-15: disclosed: NVD Published Date
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-23: other: Published date listed in advisory summary

Related threats