CVE-2023-21255

HIGH

Android - Use-After-Free in binder.c

Title source: llm
STIX 2.1

Description

In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Scores

CVSS v3 7.8
EPSS 0.0010
EPSS Percentile 26.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-416 CWE-787
Status published
Products (3)
debian/debian_linux 10.0
debian/debian_linux 11.0
google/android
Published Jul 13, 2023
Tracked Since Feb 18, 2026