VDB
CVE-2011-1823
CVE-2011-1823
PUBLISHED
KEV
CVSS 7.199999809265137 HIGH
The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.
EPSS 41.37% · 98.6th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
41.37%
98.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| android | 3.0, 2.0 | |
| n/a | n/a | n/a |
Timeline
- Jun 9, 2011 CVE Published
- Aug 17, 2021 VulnCheck KEV Exploitation
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 8, 2022 CISA KEV Added
- Sep 8, 2022 VulnCheck KEV Exploitation
- Oct 27, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jun 14, 2023 PoC Published
References
- http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f url
- http://forum.xda-developers.com/showthread.php?t=1044765 url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-1823 url
- https://nvd.nist.gov/vuln/detail/CVE-2011-1823 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67977 url
- http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6 url
- http://android.git.kernel.org/?p=platform/system/core.git;a=commit;h=b620a0b1c7ae486e979826200e8e441605b0a5d6 url
- http://android.git.kernel.org/?p=platform/system/netd.git;a=commit;h=79b579c92afc08ab12c0a5788d61f2dd2934836f url
- http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e url
- http://android.git.kernel.org/?p=platform/system/vold.git;a=commit;h=c51920c82463b240e2be0430849837d6fdc5352e url
- http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421 url
- http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html url
- http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now url
- http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue url
- http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/ technical
- http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/ technical
- http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/ exploit