{"schema_version":"1.9.0","id":"ASB-A-147802478","published":"2020-12-01T00:00:00Z","modified":"2026-09-10T15:43:18.983809180Z","aliases":["A-147802478","CVE-2020-0466"],"details":"In do_epoll_ctl and ep_loop_check_proc of eventpoll.c, there is a possible use after free due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","affected":[{"package":{"name":":linux_kernel:","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":":0"},{"fixed":":2020-12-05"}]}],"versions":["Kernel"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/kernel/common/+/52c479697c9b","https://android.googlesource.com/kernel/common/+/a9ed4a6560b8"],"severity":"High","spl":"2020-12-05","types":["EoP"],"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["5546302996892674695733181081150190713","254845254488049433364925925329909631002","61111867128246008456282430160655614650","287477108854287806242547243331052839356","68236877813091864302708093933915698115","241701986920677964397555727463466709105","277080834881712031923981486806664647673","158824667307289245702507900316174347151","7079986297794278244640125217904423066","333313324903879629285535110877405531974","75751489068667955072051408444324484418","138995473984137896688517210729817981360","178406555186694324031589384626827039474","180244627870399677721222713516771792152","38313024542004397305181903134150602153","291604657342661748843223099276439875606","257038468580260341064543362812162197302","258680882647267136425551000568036250174","82728358833382096016259715752225092144","200102018146994184616351414251937779109"],"threshold":0.9},"id":"ASB-A-147802478-2f8a7413","signature_type":"Line","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/a9ed4a6560b8","target":{"file":"fs/eventpoll.c"}},{"deprecated":false,"digest":{"function_hash":"339019174826606143645427579203886136719","length":241},"id":"ASB-A-147802478-36ff48c6","signature_type":"Function","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/a9ed4a6560b8","target":{"file":"fs/eventpoll.c","function":"clear_tfile_check_list"}},{"deprecated":false,"digest":{"function_hash":"287259407574339437852013043003131772390","length":839},"id":"ASB-A-147802478-82fec563","signature_type":"Function","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/a9ed4a6560b8","target":{"file":"fs/eventpoll.c","function":"ep_loop_check_proc"}},{"deprecated":false,"digest":{"function_hash":"52056042117655767104639557800881983778","length":2447},"id":"ASB-A-147802478-d5c667f7","signature_type":"Function","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/a9ed4a6560b8","target":{"file":"fs/eventpoll.c","function":"do_epoll_ctl"}}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-147802478.json"}}],"references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2020-12-01"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/52c479697c9b"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/a9ed4a6560b8"}]}