CVE-2023-20938
In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation...
- Published
- Feb 28, 2023
- Updated
- Aug 2, 2024
- Assigning CNA
- google_android
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 26.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
In binder_transaction_buffer_release of binder.c, there is a possible use after free due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-257685302References: Upstream kernel
Sources
3A bug trigger for CVE-2023-20938 for Android Binder.
- CVE-2023-20938-pocExploit
Local privilege escalation proof-of-concept for CVE-2023-20938, a use-after-free in Android binder, achieving root and disabling SELinux on vulnerable test builds.
Technical analysis and proof-of-concept exploit for CVE-2023-20938, a use-after-free vulnerability in the Android kernel's Binder driver, enabling local privilege escalation.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.