kernel: Use-after-free in binder.c
Published Oct 11, 2019 ·Due May 3, 2022
7.8
HIGHCVSS 3.1
EPSS 72.10%
Description
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095
Affected products
- Vendor n/a Product Android Defaultn/a
- Version KernelStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Android | n/a |
|
Configuration 2
- 8.0
Configuration 3
- 16.04
Configuration 4
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 5
Running on/with
- n/a
Configuration 6
Running on/with
- a700s
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- n/a
Configuration 16
- n/a
Configuration 17
- n/a
Configuration 18
- n/a
Configuration 19
- < 10.0.0.162\(c00e156r2p4\)
Configuration 20
- < 10.0.0.162\(c01e156r1p4\)
Configuration 21
- < 9.1.0.126\(c00e126r1p7t8\)
Configuration 22
- < 9.1.0.165\(c00e165r2p5t8\)
Running on/with
- n/a
Configuration 23
- < 9.1.0.165\(c00e165r2p5t8\)
Running on/with
- n/a
Configuration 24
- < 8.2.0.163\(c01r2p1\)
Running on/with
- n/a
Configuration 25
- < 10.0.0.170\(c786e170r2p4\)
Configuration 26
- < 9.1.0.300\(c432e4r1p11t8\)
Configuration 27
- < 10.0.0.170\(c01e170r1p4\)
Configuration 28
- < 8.0.0.377\(c00\)
Running on/with
- n/a
Configuration 29
- < 9.1.0.351\(c432e5r1p13t8\)
Running on/with
- n/a
Configuration 30
- < 9.1.0.333\(c01e333r1p1t8\)
Running on/with
- n/a
Configuration 31
- < 8.1.0.186\(c00gt\)
Running on/with
- n/a
Configuration 32
- < 9.1.0.325\(c432e4r1p12t8\)
Running on/with
- n/a
Configuration 33
- < 9.1.0.321\(c01e320r1p1t8\)
Running on/with
- n/a
Configuration 34
- < 9.0.1.171\(c675e6r1p5t8\)
Configuration 35
- < 1.0.0.190\(c00\)
Running on/with
- n/a
Configuration 36
- < 9.1.0.130\(c00e115r2p8t8\)
Running on/with
- n/a
Configuration 37
- < 9.1.0.128\(c00e112r1p6t8\)
Running on/with
- n/a
Configuration 38
- < 9.1.0.154\(c605e7r1p2t8\)
Running on/with
- n/a
Configuration 39
- < 9.1.0.154\(c605e7r1p2t8\)
Running on/with
- n/a
Configuration 40
- < 9.1.0.150\(c636e6r1p5t8\)
Running on/with
- n/a
Configuration 41
- < 9.1.0.128\(c01e112r1p6t8\)
Running on/with
- n/a
Configuration 42
- 9.1.0.321\(c786e320r1p1t8\)
Configuration 43
- < 9.1.0.312\(c00e312r1p1t8\)
Configuration 44
- < 9.1.0.200\(c605e4r1p3t8\)
Configuration 45
- < 9.1.0.200\(c635e5r1p1t8\)
Configuration 46
- < 9.1.0.246\(c432e6r1p7t8\)
Configuration 47
- < 9.1.0.297\(c605e4r1p1t8\)
Configuration 48
- < 9.1.0.210\(c01e110r1p9t8\)
Configuration 49
- < 9.1.0.351\(c00e351r1p1t8\)
Configuration 50
- < 9.1.0.200\(c636e4r1p5t8\)
Configuration 51
- < 9.1.0.200\(c636e4r1p5t8\)
Configuration 52
- < 9.1.0.201\(c636e4r1p5t8\)
Configuration 53
- < 9.1.0.201\(c636e4r1p5t8\)
Configuration 54
- < 9.1.0.201\(zafc185e4r1p8t8\)
Configuration 55
- < 9.1.0.201\(zafc185e4r1p8t8\)
Configuration 56
- < 10.1.0.214\(c10e5r4p3\)
Running on/with
- n/a
Configuration 57
- < 9.1.0.260\(c00e120r2p2\)
Running on/with
- n/a
Configuration 58
- < 9.1.0.219\(c01e18r3p2t8\)
Running on/with
- n/a
Configuration 59
- < 9.1.0.130\(c00e112r2p10t8\)
Running on/with
- n/a
Configuration 60
- < 9.1.0.156\(c185e5r1p5t8\)
Running on/with
- n/a
Configuration 61
- < 9.1.0.153\(c675e6r1p4t8\)
Running on/with
- n/a
Configuration 62
- < 9.1.0.130\(c01e112r2p10t8\)
Running on/with
- n/a
Configuration 63
- < 9.1.0.130\(c01e112r2p10t8\)
Running on/with
- n/a
Configuration 64
- < 9.1.0.130\(c00e112r2p10t8\)
Running on/with
- n/a
Configuration 65
- < 9.1.0.156\(c636e5r1p5t8\)
Running on/with
- n/a
Configuration 66
- < 9.1.0.321\(c786e320r1p1t8\)
Configuration 67
- < 10.1.0.160\(c00e160r2p11\)
Running on/with
- n/a
Configuration 68
- < 8.0.0.376\(c00\)
Running on/with
- n/a
Configuration 69
- < 9.1.0.211\(c635e2r1p4t8\)
Running on/with
- n/a
Configuration 70
- < 9.1.0.210\(c432e2r1p5t8\)
Running on/with
- n/a
Configuration 71
- < 9.1.0.212\(c00e62r1p7t8\)
Running on/with
- n/a
Configuration 72
- < 9.1.0.212\(c01e62r1p7t8\)
Running on/with
- n/a
Configuration 73
- < 9.1.0.212\(c00e62r1p7t8\)
Running on/with
- n/a
Configuration 74
- < 10.0.0.175\(c00e59r2p11\)
Running on/with
- n/a
Configuration 75
- < 10.0.0.175\(c01e59r2p11\)
Running on/with
- n/a
Configuration 76
- < 10.1.0.160\(c00e160r8p12\)
Running on/with
- n/a
Configuration 77
- < 10.1.0.231\(c10e3r3p2\)
Configuration 78
- < 10.1.0.160\(c01e160r8p12\)
Running on/with
- n/a
Configuration 79
- < 9.1.0.130\(c00e112r2p10t8\)
No data.
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
There is no mitigation required for this flaw as it does not affect shipping Red Hat Enterprise Linux kernels.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:P/I:P/A:P
Date Added
Nov 3, 2021
Patch Due
May 3, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (70 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 72.10% (0.72105) | 99.42th | v5 (v2026.06.15) |
| Aug 24, 2026 | 72.10% (0.72105) | 99.38th | v5 (v2026.06.15) |
| Jul 24, 2026 | 43.82% (0.43823) | 98.61th | v5 (v2026.06.15) |
| Jun 15, 2026 | 72.10% (0.72105) | 99.35th | v5 (v2026.06.15) |
| Jun 11, 2026 | 53.14% (0.53144) | 98.02th | v4 (v2025.03.14) |
| May 29, 2026 | 51.47% (0.51467) | 97.93th | v4 (v2025.03.14) |
| May 26, 2026 | 54.47% (0.54468) | 98.06th | v4 (v2025.03.14) |
| May 24, 2026 | 50.89% (0.50886) | 97.90th | v4 (v2025.03.14) |
| May 22, 2026 | 54.47% (0.54468) | 98.06th | v4 (v2025.03.14) |
| May 21, 2026 | 49.33% (0.49327) | 97.83th | v4 (v2025.03.14) |
| May 13, 2026 | 50.89% (0.50886) | 97.89th | v4 (v2025.03.14) |
| May 12, 2026 | 54.47% (0.54468) | 98.05th | v4 (v2025.03.14) |
| Apr 8, 2026 | 51.40% (0.51401) | 97.88th | v4 (v2025.03.14) |
| Apr 6, 2026 | 57.18% (0.57183) | 98.14th | v4 (v2025.03.14) |
| Feb 27, 2026 | 52.95% (0.52946) | 97.89th | v4 (v2025.03.14) |
| Feb 25, 2026 | 54.47% (0.54468) | 97.97th | v4 (v2025.03.14) |
| Feb 17, 2026 | 51.81% (0.51808) | 97.83th | v4 (v2025.03.14) |
| Feb 8, 2026 | 53.34% (0.53343) | 97.90th | v4 (v2025.03.14) |
| Jan 18, 2026 | 50.25% (0.50252) | 97.74th | v4 (v2025.03.14) |
| Dec 29, 2025 | 53.91% (0.53914) | 97.89th | v4 (v2025.03.14) |
| Dec 28, 2025 | 56.09% (0.56089) | 97.99th | v4 (v2025.03.14) |
| Dec 27, 2025 | 54.92% (0.54916) | 97.95th | v4 (v2025.03.14) |
| Dec 23, 2025 | 56.09% (0.56089) | 97.99th | v4 (v2025.03.14) |
| Dec 18, 2025 | 53.91% (0.53914) | 97.89th | v4 (v2025.03.14) |
| Dec 1, 2025 | 51.81% (0.51808) | 97.79th | v4 (v2025.03.14) |
| Nov 21, 2025 | 50.04% (0.50043) | 97.68th | v4 (v2025.03.14) |
| Nov 18, 2025 | 35.92% (0.35924) | 96.88th | v4 (v2025.03.14) |
| Nov 15, 2025 | 49.46% (0.49458) | 97.65th | v4 (v2025.03.14) |
| Oct 29, 2025 | 51.02% (0.51016) | 97.71th | v4 (v2025.03.14) |
| Oct 28, 2025 | 47.29% (0.47294) | 97.54th | v4 (v2025.03.14) |
| Oct 27, 2025 | 46.06% (0.46058) | 97.50th | v4 (v2025.03.14) |
| Oct 25, 2025 | 47.29% (0.47294) | 97.53th | v4 (v2025.03.14) |
| Oct 17, 2025 | 46.10% (0.46097) | 97.47th | v4 (v2025.03.14) |
| Oct 2, 2025 | 49.83% (0.49834) | 97.75th | v4 (v2025.03.14) |
| Oct 1, 2025 | 46.16% (0.46164) | 97.58th | v4 (v2025.03.14) |
| Sep 25, 2025 | 48.61% (0.48607) | 97.69th | v4 (v2025.03.14) |
| Sep 16, 2025 | 51.45% (0.51447) | 97.81th | v4 (v2025.03.14) |
| Aug 28, 2025 | 49.20% (0.49195) | 97.70th | v4 (v2025.03.14) |
| Aug 22, 2025 | 45.45% (0.45451) | 97.51th | v4 (v2025.03.14) |
| Aug 18, 2025 | 51.45% (0.51447) | 97.79th | v4 (v2025.03.14) |
| Jul 30, 2025 | 48.61% (0.48607) | 97.66th | v4 (v2025.03.14) |
| Jul 24, 2025 | 46.75% (0.46748) | 97.54th | v4 (v2025.03.14) |
| Jul 18, 2025 | 49.03% (0.49030) | 97.65th | v4 (v2025.03.14) |
| Jul 15, 2025 | 45.28% (0.45285) | 97.45th | v4 (v2025.03.14) |
| Jul 1, 2025 | 42.41% (0.42410) | 97.31th | v4 (v2025.03.14) |
| Jun 20, 2025 | 44.48% (0.44478) | 97.41th | v4 (v2025.03.14) |
| Jun 7, 2025 | 47.64% (0.47639) | 97.54th | v4 (v2025.03.14) |
| Jun 4, 2025 | 44.45% (0.44448) | 97.39th | v4 (v2025.03.14) |
| May 19, 2025 | 48.16% (0.48159) | 97.57th | v4 (v2025.03.14) |
| May 17, 2025 | 51.00% (0.51004) | 97.70th | v4 (v2025.03.14) |
| Apr 21, 2025 | 48.16% (0.48159) | 97.54th | v4 (v2025.03.14) |
| Apr 18, 2025 | 53.16% (0.53156) | 97.77th | v4 (v2025.03.14) |
| Mar 23, 2025 | 51.12% (0.51121) | 97.55th | v4 (v2025.03.14) |
| Mar 17, 2025 | 46.81% (0.46810) | 97.39th | v4 (v2025.03.14) |
| Dec 17, 2024 | 51.32% (0.51322) | 97.65th | v3 (v2023.03.01) |
| Oct 4, 2024 | 48.72% (0.48724) | 97.55th | v3 (v2023.03.01) |
| Jul 26, 2024 | 45.27% (0.45268) | 97.45th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.30% (0.00300) | 68.71th | v3 (v2023.03.01) |
| May 8, 2023 | 0.30% (0.00300) | 64.88th | v3 (v2023.03.01) |
| Mar 16, 2023 | 0.38% (0.00376) | 68.52th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.27% (0.00265) | 62.30th | v3 (v2023.03.01) |
| Mar 6, 2023 | 16.49% (0.16489) | 96.14th | v2 (v2022.01.01) |
| Apr 1, 2022 | 16.49% (0.16489) | 95.79th | v2 (v2022.01.01) |
| Feb 4, 2022 | 16.49% (0.16489) | 92.86th | v2 (v2022.01.01) |
| Feb 3, 2022 | 25.71% (0.25706) | 95.59th | v1 |
| Jan 6, 2022 | 25.71% (0.25706) | 95.54th | v1 |
| Sep 16, 2021 | 25.71% (0.25706) | 98.25th | v1 |
| Sep 14, 2021 | 4.47% (0.04473) | 83.96th | v1 |
| Sep 1, 2021 | 25.71% (0.25706) | 98.27th | v1 |
| Apr 14, 2021 | 25.71% (0.25706) | 0.00th | v1 |
References (17)
- http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html x_refsource_MISCPatchThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2019/Oct/38 mailing-listx_refsource_FULLDISCMailing ListThird Party Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en x_refsource_CONFIRMThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-2215 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1805822 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-2215
- https://seclists.org/bugtraq/2019/Nov/11 mailing-listx_refsource_BUGTRAQMailing ListPatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20191031-0005/ x_refsource_CONFIRMThird Party Advisory
- https://source.android.com/security/bulletin/2019-10-01 x_refsource_CONFIRMVendor Advisory
- https://usn.ubuntu.com/4186-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-2215 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2019-2215
Change history (0)
No recorded changes yet.