CVE-2011-1823
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Android OS Privilege Escalation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 42% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-190
מוצרים מושפעים
google: android
קישורים
- http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html ExploitIssue Tracking
- http://forum.xda-developers.com/showthread.php?t=1044765 ExploitIssue Tracking
- http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/ Exploit
- http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html ExploitIssue Tracking
- http://forum.xda-developers.com/showthread.php?t=1044765 ExploitIssue Tracking
- http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/ Exploit
- http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a… Broken Link
- http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b57… Broken Link
- http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c5192… Broken Link
- http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/ Broken Link