#VU51055 Use-after-free in Google Android - CVE-2020-11290
Published: March 2, 2021
Google Android
Description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the display component in Qualcomm chipsets in msm ioctl events due to race between the ioctl register and deregister events. A local user can run a specially crafted program to escalate privileges on the system.