{"api_version":"1","generated_at":"2026-07-23T11:21:59+00:00","cve":"CVE-2019-2215","urls":{"html":"https://cve.report/CVE-2019-2215","api":"https://cve.report/api/cve/CVE-2019-2215.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-2215","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-2215"},"summary":{"title":"CVE-2019-2215","description":"A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095","state":"PUBLIC","assigner":"security@android.com","published_at":"2019-10-11 19:15:00","updated_at":"2019-10-18 19:15:00"},"problem_types":["CWE-416"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html","name":"http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html","refsource":"MISC","tags":[],"title":"Android Binder Use-After-Free ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2019/Nov/11","name":"20191108 [slackware-security] Slackware 14.2 kernel (SSA:2019-311-01)","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: [slackware-security]  Slackware 14.2 kernel (SSA:2019-311-01)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2019/Oct/38","name":"20191018 CVE 2019-2215 Android Binder Use After Free","refsource":"FULLDISC","tags":[],"title":"Full Disclosure: CVE 2019-2215 Android Binder Use After Free","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://source.android.com/security/bulletin/2019-10-01","name":"https://source.android.com/security/bulletin/2019-10-01","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Android Security Bulletin—October 2019  |  Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html","name":"[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 2114-1] linux-4.9 security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en","name":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en","refsource":"CONFIRM","tags":[],"title":"Security Advisory - Use-after-free Vulnerability in Android Kernel","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html","name":"http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html","refsource":"MISC","tags":[],"title":"Slackware Security Advisory - Slackware 14.2 kernel Updates ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/4186-1/","name":"USN-4186-1","refsource":"UBUNTU","tags":[],"title":"USN-4186-1: Linux kernel vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html","name":"http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html","refsource":"MISC","tags":[],"title":"Android Binder Use-After-Free ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html","name":"[debian-lts-announce] 20200118 [SECURITY] [DLA 2068-1] linux security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 2068-1] linux security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.netapp.com/advisory/ntap-20191031-0005/","name":"https://security.netapp.com/advisory/ntap-20191031-0005/","refsource":"CONFIRM","tags":[],"title":"October 2019 Linux Kernel Vulnerabilities in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-2215","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-2215","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"2215","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"2215","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"google","cpe5":"android","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2019","cve_id":"2215","cve":"CVE-2019-2215","vendorProject":"Android","product":"Android Kernel","vulnerabilityName":"Android Kernel Use-After-Free Vulnerability","dateAdded":"2021-11-03","shortDescription":"Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain \"AbstractEmu.\"","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2019-2215","cwes":"CWE-416","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:16"},"epss":{"cve_year":"2019","cve_id":"2215","cve":"CVE-2019-2215","epss":"0.721050000","percentile":"0.993700000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:34"},"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-2215","ASSIGNER":"security@android.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Android","version":{"version_data":[{"version_value":"Kernel"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Elevation of privilege"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://source.android.com/security/bulletin/2019-10-01","url":"https://source.android.com/security/bulletin/2019-10-01"},{"refsource":"FULLDISC","name":"20191018 CVE 2019-2215 Android Binder Use After Free","url":"http://seclists.org/fulldisclosure/2019/Oct/38"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html","url":"http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html"},{"refsource":"CONFIRM","name":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en","url":"http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en"},{"refsource":"CONFIRM","name":"https://security.netapp.com/advisory/ntap-20191031-0005/","url":"https://security.netapp.com/advisory/ntap-20191031-0005/"},{"refsource":"BUGTRAQ","name":"20191108 [slackware-security] Slackware 14.2 kernel (SSA:2019-311-01)","url":"https://seclists.org/bugtraq/2019/Nov/11"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html","url":"http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html"},{"refsource":"UBUNTU","name":"USN-4186-1","url":"https://usn.ubuntu.com/4186-1/"},{"refsource":"MLIST","name":"[debian-lts-announce] 20200118 [SECURITY] [DLA 2068-1] linux security update","url":"https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html","url":"http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html"},{"refsource":"MLIST","name":"[debian-lts-announce] 20200302 [SECURITY] [DLA 2114-1] linux-4.9 security update","url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html"}]},"description":{"description_data":[{"lang":"eng","value":"A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095"}]}},"nvd":{"publishedDate":"2019-10-11 19:15:00","lastModifiedDate":"2019-10-18 19:15:00","problem_types":["CWE-416"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:google:android:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"2215","Ordinal":"139111","Title":"CVE-2019-2215","CVE":"CVE-2019-2215","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"2215","Ordinal":"1","NoteData":"A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095","Type":"Description","Title":null},{"CveYear":"2019","CveId":"2215","Ordinal":"2","NoteData":"2019-10-11","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"2215","Ordinal":"3","NoteData":"2020-03-02","Type":"Other","Title":"Modified"}]}}}