The print_binder_transaction_ilocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "*from *code *flags" lines in a debugfs file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Apr 30, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade kernel-toolsUpgrade python-perfUpgrade kernel-headersUpgrade perfUpgrade kernelUpgrade kernel-develUpgrade kernel-tools-libs | Dec 11, 2019 | Apr 30, 2019 |
| Ubuntu | — | Upgrade linux-awsUpgrade linux-lts-xenialUpgrade linux-fipsUpgrade linux-snapdragonUpgrade linux-hwe-edgeUpgrade linux-gcpUpgrade linux-azureUpgrade linux-hwe | Nov 19, 2024 | Apr 30, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub