The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak
Published Jun 9, 2011 ·Due Sep 29, 2022
7.8
HIGHCVSS 3.1
EPSS 41.37%
Description
The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:C/I:C/A:C
Date Added
Sep 8, 2022
Patch Due
Sep 29, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 41.37% (0.41367) | 98.63th | v5 (v2026.06.15) |
| Jun 15, 2026 | 41.63% (0.41634) | 98.50th | v5 (v2026.06.15) |
| Apr 3, 2026 | 38.34% (0.38341) | 97.21th | v4 (v2025.03.14) |
| Feb 10, 2026 | 34.38% (0.34385) | 96.88th | v4 (v2025.03.14) |
| Oct 22, 2025 | 45.79% (0.45789) | 97.45th | v4 (v2025.03.14) |
| Oct 4, 2025 | 54.88% (0.54882) | 97.97th | v4 (v2025.03.14) |
| Sep 13, 2025 | 45.41% (0.45408) | 97.53th | v4 (v2025.03.14) |
| Sep 12, 2025 | 46.81% (0.46811) | 97.60th | v4 (v2025.03.14) |
| Sep 10, 2025 | 55.58% (0.55581) | 98.00th | v4 (v2025.03.14) |
| Jul 22, 2025 | 67.78% (0.67783) | 98.49th | v4 (v2025.03.14) |
| Jul 14, 2025 | 69.26% (0.69256) | 98.55th | v4 (v2025.03.14) |
| May 31, 2025 | 73.73% (0.73728) | 98.73th | v4 (v2025.03.14) |
| Apr 30, 2025 | 68.99% (0.68987) | 98.51th | v4 (v2025.03.14) |
| Mar 30, 2025 | 74.57% (0.74567) | 98.78th | v4 (v2025.03.14) |
| Mar 29, 2025 | 70.53% (0.70525) | 98.23th | v4 (v2025.03.14) |
| Mar 17, 2025 | 74.57% (0.74567) | 98.78th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.66% (0.00656) | 80.20th | v3 (v2023.03.01) |
| Jun 29, 2024 | 0.66% (0.00656) | 79.64th | v3 (v2023.03.01) |
| Jun 20, 2024 | 0.07% (0.00073) | 31.70th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00073) | 29.69th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.17% (0.02172) | 80.27th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.17% (0.02172) | 78.34th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.17% (0.02172) | 57.15th | v2 (v2022.01.01) |
References (10)
- http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a5d6 x_refsource_CONFIRMBroken Link
- http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd2934836f x_refsource_CONFIRMBroken Link
- http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc5352e x_refsource_CONFIRMBroken Link
- http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/ x_refsource_MISCBroken Link
- http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html x_refsource_MISCExploitIssue Tracking
- http://forum.xda-developers.com/showthread.php?t=1044765 x_refsource_MISCExploitIssue Tracking
- http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-for-now/ x_refsource_MISCPress/Media Coverage
- http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/ x_refsource_MISCExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67977 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-1823 government-resourceUS Government Resource
Change history (0)
No recorded changes yet.