CVE-2019-1999: Double Free
In binderallocfreepage of binderalloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025196.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-1999.
What is the severity of CVE-2019-1999?
CVE-2019-1999 has a severity level of high.
How does CVE-2019-1999 affect Android?
CVE-2019-1999 affects Android.
Is user interaction required for exploitation of CVE-2019-1999?
No, user interaction is not needed for exploitation of CVE-2019-1999.
Where can I find more information about CVE-2019-1999?
You can find more information about CVE-2019-1999 at the following references: [http://www.securityfocus.com/bid/106851](http://www.securityfocus.com/bid/106851), [https://source.android.com/security/bulletin/2019-02-01](https://source.android.com/security/bulletin/2019-02-01), [https://www.exploit-db.com/exploits/46357/](https://www.exploit-db.com/exploits/46357/).