In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-69164715 References: Upstream kernel.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Nov 6, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade kernel-toolsUpgrade kernel-develUpgrade perfUpgrade python-perfUpgrade kernel-headersUpgrade kernelUpgrade kernel-tools-libs | Dec 27, 2019 | Nov 6, 2018 |
| Ubuntu | — | Upgrade linux-gcpUpgrade linux-azure-edgeUpgrade linux-hweUpgrade linux-azureUpgrade linux-hwe-edge | Nov 19, 2024 | Nov 6, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub