ASB-A-200688826 PUBLISHED

In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected Products

VendorProductVersions
Android:linux_kernel::0, Kernel, :0

Timeline

References

Open in Interactive Console →