CVE-2019-2215
KEV PoC ×2mass1Use-After-Free Privilege Escalation in Android Kernel (CVE-2019-2215)
CISA: Android Kernel Use-After-Free Vulnerability
CVE-2019-2215 is a use-after-free flaw (CWE-416) in the Android kernel's binder.c IPC driver that allows privilege escalation from an application to the Linux kernel. Exploitation requires no user interaction, but an attacker must either run a malicious local application or chain the bug with a vulnerability in a network-facing application. Successful exploitation yields kernel-level code execution, effectively rooting the device and giving the attacker full control over apps, data, and communications. Affected parties include Android devices with unpatched kernels (reporting at the time indicated most Android phones were affected), plus products shipping affected Android kernel code, including Google Android, Debian/Ubuntu builds, and NetApp and Huawei offerings. The flaw was publicly disclosed and patched in Android's October 2019 security updates, public proof-of-concept exploits exist, and it is listed in CISA's Known Exploited Vulnerabilities catalog with a high (72.1%) EPSS probability of exploitation; headlines confirm in-the-wild use, including a Google Play app that leveraged it to deliver spyware.
What to do: Apply vendor-supplied updates per CISA's required action — for phones and tablets, ensure the device is on the October 2019 Android security patch level or later (check Settings > About phone > Android security patch level) and patch via MDM across your fleet; NetApp, Huawei, Debian, and Ubuntu customers should install their vendors' corresponding kernel updates. Because this is a local privilege escalation with no user interaction required, also patch any network-facing applications that could be chained with it, and hunt for signs of exploitation such as unexpected root or unknown sideloaded/rooting apps on managed devices.
| google android (Android kernel, binder.c) | — |
| huawei android (Android-based devices) | — |
| debian linux (Android kernel code) | — |
| canonical ubuntu linux (Android kernel code) | — |
| netapp cloud backup | — |
| netapp data availability services | — |
| netapp hci management node | — |
| netapp service processor | — |
| netapp solidfire | — |
| netapp steelstore cloud integrated storage | — |
| netapp solidfire baseboard management controller firmware | — |
| netapp aff baseboard management controller firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
- Affected
- Android Android Kernel
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- googledebiancanonicalnetapphuawei
- Products
- android, debian linux, ubuntu linux, cloud backup, data availability services, hci management node, service processor, solidfire, steelstore cloud integrated storage, solidfire baseboard management controller firmware, aff baseboard management controller firmware, a320 firmware
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H