In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-69164715 References: Upstream kernel.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Nov 6, 2018 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-perfUpgrade kernel-develUpgrade perfUpgrade kernel-headersUpgrade kernel-toolsUpgrade kernelUpgrade kernel-tools-libs | Dec 27, 2019 | Nov 6, 2018 |
| Ubuntu | — | Upgrade linux-gcpUpgrade linux-hweUpgrade linux-azure-edgeUpgrade linux-azureUpgrade linux-hwe-edge | Nov 19, 2024 | Nov 6, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub