UBUNTU-CVE-2023-21255
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-21255
UBUNTU-CVE-2023-21255
Summary:
Details: In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References: https://ubuntu.com/security/CVE-2023-21255, https://git.kernel.org/linus/bdc1c5fac982845a58d28690cdb56db8c88a530d, https://lore.kernel.org/all/[email protected]/, https://source.android.com/docs/security/bulletin/2023-07-01, https://ubuntu.com/security/notices/USN-6338-1, https://ubuntu.com/security/notices/USN-6339-1, https://ubuntu.com/security/notices/USN-6340-1, https://ubuntu.com/security/notices/USN-6344-1, https://ubuntu.com/security/notices/USN-6349-1, https://ubuntu.com/security/notices/USN-6350-1, https://ubuntu.com/security/notices/USN-6351-1, https://ubuntu.com/security/notices/USN-6338-2, https://ubuntu.com/security/notices/USN-6339-2, https://ubuntu.com/security/notices/USN-6340-2, https://ubuntu.com/security/notices/USN-6357-1, https://ubuntu.com/security/notices/USN-6339-3, https://ubuntu.com/security/notices/USN-6339-4, https://ubuntu.com/security/notices/USN-6397-1, https://www.cve.org/CVERecord?id=CVE-2023-21255
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
