In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025196.
References
| Link | Resource |
|---|---|
| https://source.android.com/security/bulletin/2019-02-01 | Vendor Advisory |
| https://www.exploit-db.com/exploits/46357/ | Exploit Third Party Advisory VDB Entry |
| http://www.securityfocus.com/bid/106851 | Third Party Advisory VDB Entry |
| https://usn.ubuntu.com/3979-1/ | |
| https://www.debian.org/security/2019/dsa-4495 | |
| https://seclists.org/bugtraq/2019/Aug/13 |
Configurations
Information
Published : 2019-02-28 17:29
Updated : 2021-07-21 11:39
NVD link : CVE-2019-1999
Mitre link : CVE-2019-1999
JSON object : View
Products Affected
- android
CWE
CWE-415
Double Free
