CVE-2022-20154Medium· 6.4▾ SunlitIn lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product:…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel
androidRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56906High· 7.0In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition
CVE-2026-58728High· 7.0In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition
CVE-2026-55318High· 8.8In multiple locations, there is a possible use-after-free due to a race condition
CVE-2026-56915Medium· 6.4In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition
CVE-2026-56923Medium· 6.4In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition
CVE-2026-56964Medium· 6.4In multiple locations, there is a possible use-after-free due to a race condition