← לוח פגיעויות

CVE-2021-0920

בינונית 6.4 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Android Kernel Race Condition Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel

מדדים

CVSS 3.1
6.4 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
1% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-362, CWE-416

מוצרים מושפעים

linux: linux kernel; google: android; debian: debian linux

קישורים