{"id":"ASB-A-239630375","details":"In binder_inc_ref_for_node of binder.c, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-239630375","CVE-2022-20421"],"modified":"2026-05-22T15:55:21.353668239Z","published":"2022-10-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2022-10-01"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/19bb609b45fb"}],"affected":[{"package":{"name":":linux_kernel:","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":":0"},{"fixed":":2022-10-05"}]}],"versions":["Kernel"],"ecosystem_specific":{"spl":"2022-10-05","fixes":["https://android.googlesource.com/kernel/common/+/19bb609b45fb"],"types":["EoP"],"vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/19bb609b45fb","digest":{"threshold":0.9,"line_hashes":["259490984353565794537293102785524461468","267555410826440730617402025523294325463","119505457408262192768661853975109140881","142829617297976972460419980282029867651"]},"id":"ASB-A-239630375-21d423f3","deprecated":false,"target":{"file":"drivers/android/binder.c"}},{"deprecated":false,"target":{"function":"binder_inc_ref_for_node","file":"drivers/android/binder.c"},"source":"https://android.googlesource.com/kernel/common/+/19bb609b45fb","signature_type":"Function","id":"ASB-A-239630375-c131e652","digest":{"length":544,"function_hash":"144919374509308714361278497894983203773"},"signature_version":"v1"}],"severity":"High"},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-239630375.json"}}],"schema_version":"1.7.5"}