CVE-2019-2215 PUBLISHED KEV

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

EPSS 53.52% · 98.0th percentile

Risk Scores

EPSS Score
53.52%
98.0th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-riscv5.4.0-33.37, 5.4.0-31.35, 5.4.0-30.34
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:16.04:LTSlinux-azure4.13.0-1014.17, 4.11.0-1016.16, 4.13.0-1005.7
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1022.27, 4.4.0-1005.5, 4.4.0-1003.3
Ubuntu:20.04:LTSlinux-gke5.4.0-1080.86, 5.4.0-1078.84, 5.4.0-1076.82
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-139.165~14.04.1, 4.4.0-140.166~14.04.1, 4.4.0-141.167~14.04.1
Ubuntu:22.04:LTSlinux-riscv5.15.0-1015.17, 5.15.0-1028.32, 5.15.0-1027.31
Ubuntu:16.04:LTSlinux-gcp4.13.0-1012.16, 4.13.0-1011.15, 4.13.0-1008.11
Ubuntu:16.04:LTSlinux-hwe-edge4.13.0-19.22~16.04.1, 4.13.0-21.24~16.04.1, 4.13.0-25.29~16.04.2
Ubuntu:18.04:LTSlinux-snapdragon0, 4.4.0-1077.82, 4.4.0-1078.83
Ubuntu:16.04:LTSlinux-aws4.4.0-1074.84, 4.4.0-1075.85, 4.4.0-1077.87
Ubuntu:16.04:LTSlinux-hwe4.13.0-45.50~16.04.1, 4.13.0-41.46~16.04.1, 4.13.0-43.48~16.04.1
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:Pro:14.04:LTSlinux-aws0, 4.4.0-1002.2, 4.4.0-1003.3
Ubuntu:16.04:LTSlinux4.4.0-154.181, 0, 4.2.0-16.19
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1091.96+cvm1.1, 5.4.0-1090.95+cvm1.1, 5.4.0-1089.94+cvm1.2
Ubuntu:16.04:LTSlinux-kvm4.4.0-1043.49, 4.4.0-1059.66, 4.4.0-1058.65
Ubuntu:16.04:LTSlinux-raspi24.4.0-1029.36, 4.4.0-1023.29, 4.4.0-1021.27
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1128.136, 4.4.0-1105.110, 4.4.0-1106.111

Timeline

References

Open in Interactive Console →