CVE-2022-20141

7.0
HIGHCVSS v3.1 Base Score
0.14%
LOW RiskEPSS (3rd percentile)

In ip_check_mc_rcu of igmp.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege when opening and closing inet sockets with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-112551163References: Upstream kernel

Published: 6/15/2022
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

6.9

AV:L/AC:M/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

0.14%LOW Exploitation Risk
3rd percentile

This vulnerability has a 0.14% probability of being exploited in the next 30 days, ranking higher than 3% of all scored CVEs.

CWE Classification

Advertisement