CVE-2019-2215
Android Kernel Use-After-Free Vulnerability
7.8
HIGH
CVSS 3.1
⚠ KEVEPSS 72.1%
描述
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
如何修補 CVE-2019-2215
要修補 CVE-2019-2215,請將受影響套件升級到下列已修補版本。
- —升級至 4.15.4-1 或更新版本
CVE-2019-2215 正在被利用嗎?
是 — CVE-2019-2215 已列入 CISA Known Exploited Vulnerabilities (KEV) 清單,代表正在被實際利用,請立即修補。
受影響套件(1)
- from 0, < 4.15.4-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |