CVE-2019-2182

NameCVE-2019-2182
DescriptionIn the Android kernel in the kernel MMU code there is a possible execution path leaving some kernel text and rodata pages writable. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2242-1, DSA-4698-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)stretch4.9.210-1vulnerable
stretch (security)4.9.210-1+deb9u1fixed
buster4.19.118-2fixed
buster (security)4.19.118-2+deb10u1fixed
bullseye, sid5.7.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsource(unstable)4.16.5-1
linuxsourcejessie(not affected)
linuxsourcestretch4.9.210-1+deb9u1DSA-4698-1
linux-4.9sourcejessie4.9.210-1+deb9u1~deb8u1DLA-2242-1

Notes

[jessie] - linux <not-affected> (Vulnerable code not present)
Fixed by: https://git.kernel.org/linus/15122ee2c515a253b0c66a3e618bc7ebe35105eb

Search for package or bug name: Reporting problems