CVE-2019-2214: High severity Google Android vulnerability
In bindertransaction of binder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-136210786References: Upstream kernel
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.94-1Fixed in 6.12.107-1Fixed in 7.1.12-1Fixed in 7.1.13-1
Event History
Frequently Asked Questions
What is CVE-2019-2214?
CVE-2019-2214 is a vulnerability in the binder_transaction function of binder.c in the Android kernel that could allow local privilege escalation without requiring additional execution privileges.
How severe is CVE-2019-2214?
CVE-2019-2214 has a severity value of 7, indicating a high severity.
Which software versions are affected by CVE-2019-2214?
CVE-2019-2214 affects multiple versions of the Android kernel, including the Ubuntu linux-hwe, linux, linux-aws, linux-azure, linux-gcp, linux-gke, linux-hwe-edge, linux-kvm, linux-lts-trusty, linux-lts-xenial, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, and Debian linux packages.
How can I fix CVE-2019-2214?
To fix CVE-2019-2214, update your affected software to the specified remedy versions provided by the respective package maintainers.
Where can I find more information about CVE-2019-2214?
You can find more information about CVE-2019-2214 in the Android Security Bulletin from November 2019, the corresponding Ubuntu security advisory, and a Kernel Live Patch Security Notice.