CVE-2019-2215

NameCVE-2019-2215
DescriptionA use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2068-1, DLA-2114-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)stretch4.9.210-1fixed
stretch (security)4.9.210-1+deb9u1fixed
buster4.19.118-2fixed
buster (security)4.19.118-2+deb10u1fixed
bullseye, sid5.7.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsource(unstable)4.15.4-1
linuxsourcejessie3.16.81-1DLA-2068-1
linuxsourcestretch4.9.210-1
linux-4.9sourcejessie4.9.210-1~deb8u1DLA-2114-1

Notes

Fixed by: https://git.kernel.org/linus/f5cb779ba16334b45ba8946d6bfa6d9834d1527f

Search for package or bug name: Reporting problems