Google says Android zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-36971 | Use-after-free in Linux kernel network dst cache (CVE-2024-36971), exploited on Android CVE-2024-36971 is a use-after-free (CWE-416) race condition in the Linux kernel networking stack: __dst_negative_advice() clears a socket's cached destination (sk->sk_dst_cache) in the wrong order relative to RCU rules and dst_release(), which can free the destination entry while it is still referenced. The bug is reachable through UDP socket operations, and CISA catalogs the impact as remote code execution in the affected kernel (Android Kernel), although the published CVSS 3.1 vector scores a local attack vector (7.8 High, AV:L). An attacker who triggers the race gains code execution in kernel context, meaning on Android a malicious app could potentially escape its sandbox and take full control of the device, with high impact on confidentiality, integrity, and availability. Affected systems include Android devices running vulnerable kernels and Linux-based systems listed in the CPE data (upstream Linux kernel and Debian Linux), with no specific vulnerable version ranges disclosed in the available data. The flaw is being actively exploited: Google warned of in-the-wild exploitation (the issue was tracked by researcher Clement Lecigne), CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-07, and EPSS estimates a ~2.7% probability of exploitation in the next 30 days; no public PoC is known. Do: Install Android security updates from Google and device OEMs (Google has already shipped patches) and verify your device's security patch level is current. Debian and other Linux users should update kernel packages to builds containing the upstream fix for the __dst_negative_advice() race. Because CISA added this to KEV on 2024-08-07 with active exploitation, apply vendor mitigations promptly or discontinue use if mitigations are unavailable. | 7.8 | 3% | KEV |
| masson the order of billions of Android devices potentially affected pre-patch (upper bound), plus a large installed base across Linux/Debian systems |
Full article248 words · extracted from therecord.media · click to collapse
Google has patched a “high-severity” vulnerability that may be “under limited, targeted exploitation” in Android devices. In an advisory on Monday, Google said that the bug, tracked as CVE-2024-36971, impacts the Linux kernel — a core component of an operating system that serves as a bridge between the software and the physical hardware of a computer. The vulnerability allows hackers to remotely execute code on the affected device, Google said. The company hasn’t provided any details about specific attacks and which threat actor was behind them. For the exploit to be successful, the attacker would need to have system-level privileges, the highest level of access permissions. Google’s August patch addressed a total of 47 flaws, including those in Arm, Imagination Technologies, MediaTek and Qualcomm components. Most of them have been assigned a “high severity” rating. The new Android zero-day was discovered by Clement Lecigne of Google's Threat Analysis Group. He previously mostly reported on zero-day flaws exploited in espionage attacks. Earlier this year, researchers from Google warned that zero-day exploits — those that be used to compromise devices before anyone is aware they’re vulnerable — have become more common as nation-state hackers and cybercriminals find sophisticated ways to carry out their attacks. In a report in March, Google said it observed 97 zero-days exploited in the wild in 2023, compared to 62 in 2022 — a 50 percent increase. Forty-eight of the vulnerabilities were attributed to espionage actors while the remaining 49 were attributed to financially-motivated hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/android-zero-day-google-fix-august-patch