Executive brief
A use-after-free vulnerability in the ep_loop_check_proc function of eventpoll.c in the Android kernel allows for local escalation of privilege. Exploitation does not require user interaction or additional execution privileges.
Affected products
- Google Android Kernel
Timeline
- 2021-11-01: patched: Android Security Bulletin – November 2021
- 2021-12-15: disclosed: NVD Published Date
- 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-05-23: exploited: Reported as exploited in the wild in CISA KEV and advisory.