{"id":"ASB-A-239630375","details":"In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-239630375","CVE-2022-20421"],"modified":"2026-03-11T06:18:03.259091Z","published":"2022-10-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2022-10-01"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/19bb609b45fb"}],"affected":[{"package":{"name":":linux_kernel:","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":":0"},{"fixed":":2022-10-05"}]}],"versions":["Kernel"],"ecosystem_specific":{"types":["EoP"],"fixes":["https://android.googlesource.com/kernel/common/+/19bb609b45fb"],"vanir_signatures":[{"id":"ASB-A-239630375-21d423f3","source":"https://android.googlesource.com/kernel/common/+/19bb609b45fb","digest":{"line_hashes":["259490984353565794537293102785524461468","267555410826440730617402025523294325463","119505457408262192768661853975109140881","142829617297976972460419980282029867651"],"threshold":0.9},"deprecated":false,"signature_version":"v1","signature_type":"Line","target":{"file":"drivers/android/binder.c"}},{"id":"ASB-A-239630375-c131e652","source":"https://android.googlesource.com/kernel/common/+/19bb609b45fb","digest":{"length":544,"function_hash":"144919374509308714361278497894983203773"},"deprecated":false,"signature_version":"v1","signature_type":"Function","target":{"file":"drivers/android/binder.c","function":"binder_inc_ref_for_node"}}],"severity":"High","spl":"2022-10-05"},"database_specific":{"source":"https://storage.googleapis.com/android-osv-test/ASB-A-239630375.json"}}],"schema_version":"1.7.5"}