SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-2215

Android Kernel Use-After-Free Vulnerability

KEVHIGH 7.8EPSS 72.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
72.10% probability · 99th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022
Weakness
CWE-416
Affected
google/android · debian/debian linux · canonical/ubuntu linux · netapp/cloud backup · netapp/data availability services · netapp/hci management node · netapp/service processor · netapp/solidfire · netapp/steelstore cloud integrated storage · netapp/solidfire baseboard management controller firmware · netapp/aff baseboard management controller firmware · netapp/a320 firmware · netapp/c190 firmware · netapp/a220 firmware · netapp/fas2720 firmware · netapp/fas2750 firmware · netapp/a800 firmware · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · +40 more
Source
security@android.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-2215

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.