CVE-2021-0920 PUBLISHED KEV

In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel

EPSS 0.91% · 75.6th percentile

Risk Scores

EPSS Score
0.91%
75.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSlinux-azure4.13.0-1016.19, 4.15.0-1046.50, 4.15.0-1045.49
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1048.51, 4.15.0-1073.78, 4.15.0-1072.76
Ubuntu:Pro:FIPS:18.04:LTSlinux-gcp-fips4.15.0-1001.1, 0
Ubuntu:18.04:LTSlinux-snapdragon4.15.0-1099.108, 0, 4.4.0-1077.82
Ubuntu:18.04:LTSlinux-gkeop-5.45.4.0-1013.14~18.04.1, 0, 5.4.0-1001.1
Ubuntu:20.04:LTSlinux-bluefield5.4.0-1013.16, 0, 5.4.0-1007.10
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-aws-fips5.4.0-1021.21+fips2, 0
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-gcp-fips0, 5.4.0-1021.21+fips1
Ubuntu:20.04:LTSlinux-raspi25.4.0-1006.6, 5.4.0-1004.4, 5.3.0-1015.17
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips0, 4.4.0-1002.2, 4.4.0-1001.1
Ubuntu:18.04:LTSlinux-hwe-edge5.3.0-23.25~18.04.1, 5.3.0-22.24~18.04.1, 5.3.0-19.20~18.04.2
Ubuntu:Pro:16.04:LTSlinux4.3.0-1.10, 4.3.0-2.11, 4.4.0-214.246
Ubuntu:20.04:LTSlinux-aws-5.85.8.0-1038.40~20.04.1, 5.8.0-1035.37~20.04.1, 0
Ubuntu:Pro:FIPS:20.04:LTSlinux-fips0, 5.4.0-1007.8
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:Pro:14.04:LTSlinux-aws4.4.0-1025.26, 0, 4.4.0-1002.2
Ubuntu:Pro:FIPS:18.04:LTSlinux-fips0, 4.15.0-1011.12
Ubuntu:20.04:LTSlinux-oracle-5.115.11.0-1016.17~20.04.1, 5.11.0-1013.14~20.04.1, 5.11.0-1008.8~20.04.1
Ubuntu:20.04:LTSlinux-oem-5.135.13.0-1009.10, 5.13.0-1010.11, 0
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-fips4.15.0-1067.76, 4.15.0-1046.53, 4.15.0-1048.55

…and 73 more

Timeline

References

Open in Interactive Console →