important · Mobile — Android Kernel
Android classifies a TIPC fragment-reassembly double-free as no-interaction remote kernel code execution, but stock-handset reachability remains unknown.
Affects
Android kernels containing the vulnerable Linux TIPC fragment-reassembly implementation.
Attacker-controlled fragments delivered to an enabled TIPC transport can leave a stale skb pointer that is freed twice after validation fails.
Detail and 3 sources
Google classifies the result as no-interaction kernel code execution, but no cited source establishes a reachable TIPC bearer on a factory-stock handset.
Chain to watch
Deliver attacker-controlled fragments to an enabled Android TIPC transport→↓Trigger the fragment-reassembly double-free→↓Reach kernel code execution→↓A stock-handset transport and attacker-reachable bearer have not been established.
Unverified chainAudit shipping OEM kernel configurations and bearer setup, then reproduce delivery on a bootloader-locked handset.
This remains Secondary because the published fix was not read for this brief.