{"schema_version":"1.9.0","id":"ASB-A-218836280","published":"2022-06-01T00:00:00Z","modified":"2026-09-10T15:43:18.983809180Z","aliases":["A-218836280","CVE-2021-4154"],"details":"In cgroup1_parse_param of cgroup-v1.c, there is a possible container breakout  due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","affected":[{"package":{"name":":linux_kernel:","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":":0"},{"fixed":":2022-06-05"}]}],"versions":["Kernel"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/kernel/common/+/811763e3beb6c"],"severity":"High","spl":"2022-06-05","types":["EoP"],"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["191251821101608297518000102230053641","161478230760747823243509515755670125340","53748005745504328288671075488780645792","268088281257053229139836659380680159012"],"threshold":0.9},"id":"ASB-A-218836280-0a0279e2","signature_type":"Line","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/811763e3beb6c","target":{"file":"kernel/cgroup/cgroup-v1.c"}},{"deprecated":false,"digest":{"function_hash":"43562121027514138802384445818688810638","length":1976},"id":"ASB-A-218836280-f8ce5168","signature_type":"Function","signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/811763e3beb6c","target":{"file":"kernel/cgroup/cgroup-v1.c","function":"cgroup1_parse_param"}}]},"database_specific":{"source":"https://storage.googleapis.com/android-osv/ASB-A-218836280.json"}}],"references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2022-06-01"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/811763e3beb6c"}]}