Back

HIGH

kernel: use after free due to race condition in the video driver leads to local privilege escalation

Published Sep 6, 2019

Description

In the Android kernel in the video driver there is a use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Affected products

Remediation

Red Hat statement

This issue is rated as having Moderate impact, because of the need of additional privileges (usually local console user) to access the video device driver.

Red Hat mitigation

To mitigate this issue, prevent modules v4l2-common, v4l2-dv-timings from being loaded if not being used for primary display. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Sep 6, 2019
Updated Aug 4, 2024
Reserved Feb 28, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 3, 2019