Use-after-free in Google Android - CVE-2019-2215
Published: October 11, 2019 / Updated: April 19, 2024
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Affected software
Slackware Linux
linux-4.4.199/kernel-generic
linux-4.4.199/kernel-huge
linux-4.4.199/kernel-modules
linux-4.4.199/kernel-headers
How to mitigate CVE-2019-2215
linux-4.4.199/kernel-huge - update to 4.4.199
linux-4.4.199/kernel-modules - update to 4.4.199
linux-4.4.199/kernel-headers - update to 4.4.199_smp
Links to Public Exploits and PoC-codes
- Exploit #9741 - CVE-2019-2215 (This is a critical UAF vulnerability exploit that affected the android binder IPC system used in the wild and discovered by P0) (April 19, 2024)
- Exploit #9546 - CVE-2019-2215-HuaweiP20Lite (Exploit for CVE-2019-2215 (bad binder) for Huawei P20 Lite) (February 8, 2024)
- Exploit #9452 - CVE-2019-2215 (Exploit for Bad Binder) (December 21, 2023)
- Exploit #5875 - Android - Binder Driver Use-After-Free (June 17, 2021)
- Exploit #5766 - Android Binder - Use-After-Free (Metasploit) (June 17, 2021)
- Exploit #4758 - CVE-2019-2215 (PoC for old Binder vulnerability (based on P0 exploit)) (October 28, 2020)
- Exploit #4677 - android-kernel-exploitation-ashfaq-CVE-2019-2215 (android-kernel-exploitation-ashfaq-CVE-2019-2215 docker setup for mac users ) (October 5, 2020)
External References
- http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
- http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html
- http://seclists.org/fulldisclosure/2019/Oct/38
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://seclists.org/bugtraq/2019/Nov/11
- https://security.netapp.com/advisory/ntap-20191031-0005/
- https://source.android.com/security/bulletin/2019-10-01
- https://usn.ubuntu.com/4186-1/