CVE-2019-2111: Use After Free
In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remote code execution in the netd server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-122856181.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable over the network, requires no privileges, and does not require user interaction. Successful exploitation could result in remote code execution in the netd server.
Which Android versions are identified as affected?
The provided data identifies Android 9 as affected. No other Android versions are specified.
What security impact could successful exploitation have?
The CVSS vector indicates high impact to confidentiality, integrity, and availability. The described use-after-free condition may allow heap memory corruption and remote code execution in netd.