Impact
The vulnerability is a race condition in the handle_unmap_req function of tip can corrupt memory. Attackers can exploit the timing issue to gain elevated privileges on the device without needing to run The flaw does not allow for remote exploitation or broader access beyond the local system.
Affected Systems
Google Android devices that include the TIPC Virtio driver in tipc_virtio_dev.c are impacted. No specific Android version or build is listed, so all releases containing this driver are potentially affected.
Risk and Exploitability
The CVSS score is 6.4, indicating moderate severity. The EPSS score is 0.00054, and the vulnerability is not listed in the CISA KEV catalog. Because no user interaction is required, the attack is local and can be executed by any user with access to the device. The risk is significant for users who run untrusted code or who have local access to the system.
OpenCVE Enrichment