Use-after-free in Google Android - CVE-2019-2215

 

Use-after-free in Google Android - CVE-2019-2215

Published: October 11, 2019 / Updated: April 19, 2024


Vulnerability identifier: #VU35165
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2215
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095


Affected software

Google Android
Slackware Linux
linux-4.4.199/kernel-generic
linux-4.4.199/kernel-huge
linux-4.4.199/kernel-modules
linux-4.4.199/kernel-headers

How to mitigate CVE-2019-2215

Install update from vendor's website.

linux-4.4.199/kernel-generic - update to 4.4.199
linux-4.4.199/kernel-huge - update to 4.4.199
linux-4.4.199/kernel-modules - update to 4.4.199
linux-4.4.199/kernel-headers - update to 4.4.199_smp

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins