Junglewise Threat Intelligence

CVE-2019-2215: Android Kernel Use-After-Free Vulnerability

CVE-2019-2215 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Debian Linux, Google Android. Vendors: Android, Debian, Google.

Executive brief

A use-after-free vulnerability in the Android Kernel binder.c driver allows a local malicious application to escalate privileges to the Linux Kernel. The flaw does not require user interaction but necessitates local code execution or a chained vulnerability in a network-facing application.

Affected products

  • Google Android -
  • Debian Debian Linux 8.0

Timeline

  • 2019-10-01: advisory: Android Security Bulletin published
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats