SB2019101149 - Use-after-free in Google, Google Android



SB2019101149 - Use-after-free in Google, Google Android

Published: October 11, 2019 Updated: April 19, 2024

Security Bulletin ID SB2019101149
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Use-after-free (CVE-ID: CVE-2019-2215)

The vulnerability allows a local authenticated user to execute arbitrary code.

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095


Remediation

Install update from vendor's website.