Information disclosure in Google Android - CVE-2019-9455

 

Information disclosure in Google Android - CVE-2019-9455

Published: September 7, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU35560
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9455
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local privileged user to gain access to sensitive information.

In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.


Affected software

Google Android
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
kernel (Red Hat package)

How to mitigate CVE-2019-9455

Install update from vendor's website.

kernel (Red Hat package) - update to 4.18.0-240.el8

External References

Related Security Bulletins