CVE-2011-1823
KEVmassPrivilege Escalation to Root via Netlink Spoofing in Android vold Daemon
CISA: Android OS Privilege Escalation Vulnerability
The vold volume manager daemon in Android trusts messages arriving on a PF_NETLINK socket without authenticating their source, so a local process can send spoofed netlink messages to the daemon. A malicious app running on the device can abuse this trust to have vold execute code on its behalf with elevated privileges. A successful attacker gains root privileges, giving full control of the device and the ability to install software or modify the system. The flaw dates to 2011 and was weaponized in the GingerBreak rooting exploit and the Exploit.AndroidOS.Lotoor malware; CISA added it to the Known Exploited Vulnerabilities catalog on 2022-09-08, confirming in-the-wild exploitation. EPSS currently assigns a 41.6% probability of exploitation in the next 30 days (99th percentile), and the required action is to apply updates per vendor instructions.
What to do: Apply updates per vendor instructions as required by CISA's KEV listing, prioritizing legacy devices still running 2011-era Android that cannot receive patches, and retire or isolate them if updates are unavailable. Because this is a local privilege escalation, review devices that permit sideloading or untrusted apps and check rooted devices for signs of the Exploit.AndroidOS.Lotoor malware. Federal agencies should track the KEV remediation deadline.
| Android OS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. This vulnerability is associated with GingerBreak and Exploit.AndroidOS.Lotoor.
- Affected
- Android Android OS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Android
- Products
- Android OS
- Weakness
- CWE-189
In the news0 stories
No ingested article mentions this CVE yet.