CVE-2019-2030: Use After Free
Published Apr 1, 2019
·Updated
In removeInterfaceAddress of NetworkController.cpp, there is a possible use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-119496789.
Affected Software
2 affected components
Google Android=9.0
Google Android
Remediation
Patch Available
Event History
Apr 1, 2019
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Apr 19, 2019
CVE Published
via MITRE·07:24 PM
Data Sourced
via MITRE·07:24 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-2030?
CVE-2019-2030 has a critical severity rating due to its potential to allow remote code execution without requiring user interaction.
2
How do I fix CVE-2019-2030?
To fix CVE-2019-2030, update to the latest Android 9 security patch provided by Google.
3
Which versions of Android are affected by CVE-2019-2030?
CVE-2019-2030 affects Android version 9.0.
4
Is user interaction required to exploit CVE-2019-2030?
No, user interaction is not needed for exploitation of CVE-2019-2030.
5
What type of vulnerability is CVE-2019-2030?
CVE-2019-2030 is classified as a use after free vulnerability.