← All CVEs

CVE-2019-2215

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2022-05-03

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

7.8
CVSS
72.1%
EPSS (exploit prob.)
99th
EPSS percentile
2019-10-11
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
googleandroidall versions
debiandebian_linux8.0
canonicalubuntu_linux16.04
netappcloud_backupall versions
netappdata_availability_servicesall versions
netapphci_management_nodeall versions
netappservice_processorall versions
netappsolidfireall versions
netappsteelstore_cloud_integrated_storageall versions
netappsolidfire_baseboard_management_controller_firmwareall versions
netappsolidfire_baseboard_management_controllerall versions
netappaff_baseboard_management_controller_firmwareall versions
netappaff_baseboard_management_controllera700s
netappa320_firmwareall versions
netappa320all versions
netappc190_firmwareall versions
netappc190all versions
netappa220_firmwareall versions
netappa220all versions
netappfas2720_firmwareall versions
netappfas2720all versions
netappfas2750_firmwareall versions
netappfas2750all versions
netappa800_firmwareall versions
netappa800all versions
netapph300s_firmwareall versions
netapph300sall versions
netapph500s_firmwareall versions
netapph500sall versions
netapph700s_firmwareall versions
netapph700sall versions
netapph410s_firmwareall versions
netapph410sall versions
netapph410c_firmwareall versions
netapph410call versions
netapph610s_firmwareall versions
netapph610sall versions
huaweialp-al00b_firmware< 10.0.0.162\(c00e156r2p4\)
huaweialp-al00ball versions
huaweialp-tl00b_firmware< 10.0.0.162\(c01e156r1p4\)

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-2215