First published: Mon Feb 04 2019(Updated: )
In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025196.
Credit: security@android.com security@android.com security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Debian | =9.0 | |
Debian | =10.0 | |
Ubuntu Linux | =19.04 | |
Android | ||
Ubuntu | =19.04 | |
debian/linux | 5.10.223-1 5.10.234-1 6.1.123-1 6.1.128-1 6.12.12-1 6.12.17-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-1999.
CVE-2019-1999 has a severity level of high.
CVE-2019-1999 affects Android.
No, user interaction is not needed for exploitation of CVE-2019-1999.
You can find more information about CVE-2019-1999 at the following references: [http://www.securityfocus.com/bid/106851](http://www.securityfocus.com/bid/106851), [https://source.android.com/security/bulletin/2019-02-01](https://source.android.com/security/bulletin/2019-02-01), [https://www.exploit-db.com/exploits/46357/](https://www.exploit-db.com/exploits/46357/).