CVE-2019-2215
high · 7.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2022-05-03
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
7.8
CVSS
72.1%
EPSS (exploit prob.)
99th
EPSS percentile
2019-10-11
Published
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-416
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| android | all versions | |
| debian | debian_linux | 8.0 |
| canonical | ubuntu_linux | 16.04 |
| netapp | cloud_backup | all versions |
| netapp | data_availability_services | all versions |
| netapp | hci_management_node | all versions |
| netapp | service_processor | all versions |
| netapp | solidfire | all versions |
| netapp | steelstore_cloud_integrated_storage | all versions |
| netapp | solidfire_baseboard_management_controller_firmware | all versions |
| netapp | solidfire_baseboard_management_controller | all versions |
| netapp | aff_baseboard_management_controller_firmware | all versions |
| netapp | aff_baseboard_management_controller | a700s |
| netapp | a320_firmware | all versions |
| netapp | a320 | all versions |
| netapp | c190_firmware | all versions |
| netapp | c190 | all versions |
| netapp | a220_firmware | all versions |
| netapp | a220 | all versions |
| netapp | fas2720_firmware | all versions |
| netapp | fas2720 | all versions |
| netapp | fas2750_firmware | all versions |
| netapp | fas2750 | all versions |
| netapp | a800_firmware | all versions |
| netapp | a800 | all versions |
| netapp | h300s_firmware | all versions |
| netapp | h300s | all versions |
| netapp | h500s_firmware | all versions |
| netapp | h500s | all versions |
| netapp | h700s_firmware | all versions |
| netapp | h700s | all versions |
| netapp | h410s_firmware | all versions |
| netapp | h410s | all versions |
| netapp | h410c_firmware | all versions |
| netapp | h410c | all versions |
| netapp | h610s_firmware | all versions |
| netapp | h610s | all versions |
| huawei | alp-al00b_firmware | < 10.0.0.162\(c00e156r2p4\) |
| huawei | alp-al00b | all versions |
| huawei | alp-tl00b_firmware | < 10.0.0.162\(c01e156r1p4\) |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
- http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html
- http://seclists.org/fulldisclosure/2019/Oct/38
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://seclists.org/bugtraq/2019/Nov/11
- https://security.netapp.com/advisory/ntap-20191031-0005/
- https://source.android.com/security/bulletin/2019-10-01
- https://usn.ubuntu.com/4186-1/
- http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html
- http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html
- http://seclists.org/fulldisclosure/2019/Oct/38
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://seclists.org/bugtraq/2019/Nov/11
- https://security.netapp.com/advisory/ntap-20191031-0005/
- https://source.android.com/security/bulletin/2019-10-01
- https://usn.ubuntu.com/4186-1/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-2215
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-2215