CISA Known Exploited Vulnerability

CVE-2019-2215

Android · Android Kernel

Android Kernel Use-After-Free Vulnerability

Date added
BOD 22-01 due date
CWE CWE-416
Ransomware Unknown

CISA description

Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."

Required action

Apply updates per vendor instructions.