CVE-2019-2181

HIGH

Android kernel - Privilege Escalation

Title source: llm
STIX 2.1

Description

In binder_transaction of binder.c in the Android kernel, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4157-1/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4157-2/

Scores

CVSS v3 7.8
EPSS 0.0041
EPSS Percentile 32.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-190 CWE-787
Status published
Products (1)
google/android
Published Sep 05, 2019
Tracked Since Feb 18, 2026