CVE-2020-0423: Use After Free
In binderreleasework of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-161151868References: N/A
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0423?
CVE-2020-0423 is considered a high severity vulnerability that allows for local escalation of privilege due to a use-after-free error.
How do I fix CVE-2020-0423?
To fix CVE-2020-0423, update your affected Android or Debian kernel to the recommended versions such as 5.10.223-1 or later.
What systems are affected by CVE-2020-0423?
CVE-2020-0423 affects Google Android and Debian Linux version 9.0 and earlier.
Can CVE-2020-0423 be exploited without user interaction?
Yes, CVE-2020-0423 can be exploited without any user interaction required.
What type of vulnerability is CVE-2020-0423?
CVE-2020-0423 is a use-after-free vulnerability found in the binder_release_work function of the Android kernel.