FlawAtlas
Search the atlas
UBUNTU-CVE-2019-2181 High

UBUNTU-CVE-2019-2181

In binder_transaction of binder.c in the Android kernel, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

Exploit probability Not scored
Published September 5, 2019
Required by Not available
Last source change August 18, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS linux-gke-5.0

6 explicit affected versions

Ubuntu:18.04:LTS linux-hwe

16 explicit affected versions

Ubuntu:18.04:LTS linux-hwe-edge

10 explicit affected versions

Ubuntu:18.04:LTS linux-oem-osp1

7 explicit affected versions

Ubuntu:Pro:14.04:LTS linux

191 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-aws

120 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-azure

121 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-lts-xenial

165 explicit affected versions

Ubuntu:18.04:LTS linux-azure

35 explicit affected versions

Ubuntu:18.04:LTS linux-gcp

30 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related USN-4157-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2019-2181

In binder_transaction of binder.c in the Android kernel, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

View original source

05 / REFERENCES

Further evidence