Description: Use-after-free in Android xt_qtaguid References: https://source.android.com/security/bulletin/2021-03-01 https://android.googlesource.com/kernel/common/+/2bd81ced0685922df12f4be3338ea632805624e9 Notes: carnil> Bulletin refers to upstream kernel but unconfirmed. According carnil> to Moritz this is just in Android specific xt_qtaguid code and carnil> so actually not "upstream kernel". bwh> The bulletin links to source commits which are definitely not bwh> touching upstream code. Bugs: upstream: N/A "Vulnerable code not present" 5.10-upstream-stable: N/A "Vulnerable code not present" 4.19-upstream-stable: N/A "Vulnerable code not present" 4.9-upstream-stable: N/A "Vulnerable code not present" sid: N/A "Vulnerable code not present" 4.19-buster-security: N/A "Vulnerable code not present" 4.9-stretch-security: N/A "Vulnerable code not present"