HIGH · 7.8

CVE-2019-2215

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require ...

Vulnerability Description

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GoogleAndroid-
DebianDebian Linux8.0
CanonicalUbuntu Linux16.04
NetappCloud Backup-
NetappData Availability Services-
NetappHci Management Node-
NetappService Processor-
NetappSolidfire-
NetappSteelstore Cloud Integrated Storage-
NetappSolidfire Baseboard Management Controller Firmware-
NetappSolidfire Baseboard Management Controller-
NetappAff Baseboard Management Controller Firmware-
NetappAff Baseboard Management Controllera700s
NetappA320 Firmware-
NetappA320-
NetappC190 Firmware-
NetappC190-
NetappA220 Firmware-
NetappA220-
NetappFas2720 Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-2215?

CVE-2019-2215 is a vulnerability with a CVSS score of 7.8 (HIGH). A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require ...

How severe is CVE-2019-2215?

CVE-2019-2215 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-2215?

Check the references section above for vendor advisories and patch information. Affected products include: Google Android, Debian Debian Linux, Canonical Ubuntu Linux, Netapp Cloud Backup, Netapp Data Availability Services.