In vtdokdgkb_ioctl of keyboard.c, there is a possible use after free read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.
{ "vanir_signatures": [ { "digest": { "length": 2516.0, "function_hash": "110408221018334417520596095852485174859" }, "id": "PUB-A-174904705-1047c464", "source": "https://android.googlesource.com/kernel/common/+/82e61c3909db51d91b9d3e2071557b6435018b80", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/tty/vt/keyboard.c", "truncated_path_level": 1.0, "function": "vt_do_kdgkb_ioctl" }, "signature_type": "Function" }, { "digest": { "threshold": 0.9, "line_hashes": [ "194275741008887581683660773592281145481", "8315228988574000327071456939097433976", "80600477583606619659672096950384974720", "104857375737196067858664114120600498002", "201901347788230331230696806230515149421", "2675575038703807678240452601510427040", "125133215507300073148428151418142485320", "33269433147810158561824798089714149065", "120651608584128343493135990292904560024", "66292776179084018434320120933735435649", "5046354201908593435931698324303028830", "38580054058956432928299504579367400466", "68439981818148735403637258396168443365", "102072498919483881386871395440340172168", "91483627167664302979667418767148165049" ] }, "id": "PUB-A-174904705-2fb767ef", "source": "https://android.googlesource.com/kernel/common/+/82e61c3909db51d91b9d3e2071557b6435018b80", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/tty/vt/keyboard.c", "truncated_path_level": 1.0 }, "signature_type": "Line" }, { "digest": { "length": 294.0, "function_hash": "158862159774245439923770722094736757362" }, "id": "PUB-A-174904705-3d77ffa0", "source": "https://android.googlesource.com/kernel/common/+/82e61c3909db51d91b9d3e2071557b6435018b80", "deprecated": false, "signature_version": "v1", "target": { "file": "drivers/tty/vt/keyboard.c", "truncated_path_level": 1.0, "function": "k_fn" }, "signature_type": "Function" } ], "fixes": [ "https://android.googlesource.com/kernel/common/+/82e61c3909db51d91b9d3e2071557b6435018b80" ], "spl": "2021-05-05", "severity": "Moderate", "types": [ "ID" ] }