CVE-2019-2215
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Android Kernel Use-After-Free Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 44% (אחוזון 100) נכון ל-4/8/2026
- CWE
- CWE-416
מוצרים מושפעים
google: android; debian: debian linux; canonical: ubuntu linux; netapp: cloud backup; netapp: data availability services; netapp: hci management node; netapp: service processor; netapp: solidfire; netapp: steelstore cloud integrated storage; netapp: solidfire baseboard management controller firmware; netapp: solidfire baseboard management controller; netapp: aff baseboard management controller firmware; netapp: aff baseboard management controller; netapp: a320 firmware; netapp: a320
קישורים
- https://source.android.com/security/bulletin/2019-10-01 Vendor Advisory
- https://source.android.com/security/bulletin/2019-10-01 Vendor Advisory
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackw… PatchThird Party AdvisoryVDB Entry
- https://seclists.org/bugtraq/2019/Nov/11 Mailing ListPatchThird Party Advisory
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackw… PatchThird Party AdvisoryVDB Entry
- https://seclists.org/bugtraq/2019/Nov/11 Mailing ListPatchThird Party Advisory
- http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html ExploitThird Party AdvisoryVDB Entry