{"id":"ASB-A-204573007","details":"In ep_loop_check_proc of eventpoll.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-204573007","CVE-2021-1048"],"modified":"2026-09-18T15:47:37.392928379Z","published":"2021-11-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2021-11-01"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/77f4689de17c0887775bb77896f4cc11a39bf848"}],"affected":[{"package":{"name":":linux_kernel:","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":":0"},{"fixed":":2021-11-06"}]}],"versions":["Kernel"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/kernel/common/+/77f4689de17c0887775bb77896f4cc11a39bf848"],"severity":"High","spl":"2021-11-06","types":["EoP"],"vanir_signatures":[{"id":"ASB-A-204573007-2fe8de59","signature_type":"Line","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/77f4689de17c0887775bb77896f4cc11a39bf848","target":{"file":"fs/eventpoll.c"},"deprecated":false,"digest":{"line_hashes":["87738847746414484461941344870068227438","214976600644941457966157392288138396784","219994842081940744527435928281342041982","251510000383263481098954132756262779292","68236877813091864302708093933915698115","13233711005510888625002106547747501452"],"threshold":0.9}},{"digest":{"function_hash":"333290089620669436895702994728217173095","length":875},"id":"ASB-A-204573007-63ba0478","signature_type":"Function","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/77f4689de17c0887775bb77896f4cc11a39bf848","target":{"file":"fs/eventpoll.c","function":"ep_loop_check_proc"},"deprecated":false}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-204573007.json"}}],"schema_version":"1.9.0"}