CVE-2019-2215: Android Kernel Use-After-Free Vulnerability
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Other sources
Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1
Event History
Frequently Asked Questions
What is CVE-2019-2215?
CVE-2019-2215 is a use-after-free vulnerability in the Android Kernel.
How does CVE-2019-2215 affect Android Kernel?
CVE-2019-2215 allows an elevation of privilege from an application to the Linux Kernel.
What is the severity of CVE-2019-2215?
CVE-2019-2215 has a severity rating of high.
How can CVE-2019-2215 be exploited?
Exploiting CVE-2019-2215 requires either the installation of a malicious local application or a separate vulnerability in a network fa…
Are there any references for CVE-2019-2215?
References for CVE-2019-2215 can be found at the following links: [Link 1](https://source.android.com/security/bulletin/2019-10-01), [Link 2](http://seclists.org/fulldisclosure/2019/Oct/38), [Link 3](http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html).