CVE-2019-1999

In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025196.
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

History

21 Nov 2024, 04:37

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/106851 - Broken Link () http://www.securityfocus.com/bid/106851 - Broken Link
References () https://seclists.org/bugtraq/2019/Aug/13 - Mailing List, Third Party Advisory () https://seclists.org/bugtraq/2019/Aug/13 - Mailing List, Third Party Advisory
References () https://source.android.com/security/bulletin/2019-02-01 - Vendor Advisory () https://source.android.com/security/bulletin/2019-02-01 - Vendor Advisory
References () https://usn.ubuntu.com/3979-1/ - Third Party Advisory () https://usn.ubuntu.com/3979-1/ - Third Party Advisory
References () https://www.debian.org/security/2019/dsa-4495 - Third Party Advisory () https://www.debian.org/security/2019/dsa-4495 - Third Party Advisory
References () https://www.exploit-db.com/exploits/46357/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/46357/ - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2019-02-28 17:29

Updated : 2024-11-21 04:37


NVD link : CVE-2019-1999

Mitre link : CVE-2019-1999

CVE.ORG link : CVE-2019-1999


JSON object : View

Products Affected

canonical

  • ubuntu_linux

google

  • android

debian

  • debian_linux
CWE
CWE-415

Double Free