Lucene search

K
osvGoogleOSV:ASB-A-320661088
HistoryJun 01, 2024 - 12:00 a.m.

Unintend failure in binder_transaction lead to ref->proc UAF

2024-06-0100:00:00
Google
osv.dev
2
binder_transaction
arbitrary code execution
local privilege escalation
kernel
software
user interaction not needed

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%

In binder_alloc_copy_to_buffer of binder.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

CPENameOperatorVersion
:linux_kernel:eqKernel

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.2%