Junglewise Threat Intelligence

CVE-2011-1823: Android OS Privilege Escalation Vulnerability

CVE-2011-1823 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-09-08

Technologies: Google Android. Vendors: Android, Google.

Executive brief

The vold volume manager daemon in Android trusts messages from a PF_NETLINK socket, allowing local users to execute arbitrary code and gain root privileges. The vulnerability stems from a signedness error in the DirectVolume::handlePartitionAdded method where a negative index bypasses a maximum-only integer check, leading to memory corruption.

Affected products

  • Google Android 2.x before 2.3.4, 3.0

Timeline

  • 2011-04-21: exploited: GingerBreak exploit released
  • 2011-05-03: patched: Google patches GingerBreak exploit
  • 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog