CVE-2019-2215

Exp

A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing application.Product: AndroidAndroid ID: A-141720095

Published: 2019-10-11 Last update: 2025-10-24 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2019-2215 is rated Critical Active Threat (87.5/100): CVSS High severity, with high exploitation likelihood (EPSS 51.47%, 98th percentile). Core evidence: CISA KEV confirms active exploitation (added 2021-11-03) affecting Android / Android Kernel. a weakness (CWE-416) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

CISA KEV Record for CVE-2019-2215

Name: Android Kernel Use-After-Free Vulnerability · CISA KEV detail

Exploit added: 2021-11-03

Action due: 2022-05-03

Required action: Apply updates per vendor instructions.

Public exploit references (Exploit-DB) for CVE-2019-2215

EDB-ID Source Kind Published Link
48129 exploit_db edb 2020-02-24 Exploit-DB ↗
47463 exploit_db edb 2019-10-04 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2019-2215

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-05-29 54.47% 51.47% -3.00%
2 2026-05-26 50.89% 54.47% +3.58%
3 2026-05-24 50.89%

Full EPSS history (77 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2019-2215

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.8 3.1 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.8 5.9 [email protected]
7.8 3.1 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:L)
A normal user session is enough; they don’t have to be admin.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.8 5.9 134c704f-9b21-4f2e-91b3-4a467353bcc0
4.6 2.0 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
3.9 6.4 [email protected]

Weakness enumeration for CVE-2019-2215

OS Trackers for CVE-2019-2215

vendor priority summary link
debian not yet assigned CVE-2019-2215 not yet assigned priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2019-2215
redhat medium https://access.redhat.com/security/cve/CVE-2019-2215
ubuntu high CVE-2019-2215 high priority: Ubuntu including 95 source packages (linux, linux-aws, …), 888 status rows across 11 suites (bionic, disco, eoan, focal, jammy, noble, oracular, plucky, trusty, upstream, xenial): DNE 603, not-affected 171, released 107, ignored 7. https://ubuntu.com/security/CVE-2019-2215

Affected software / configurations for CVE-2019-2215

Vendor Product Version Raw CPE
google android cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
debian debian_linux 8.0 cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
canonical ubuntu_linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
netapp cloud_backup cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
netapp data_availability_services cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*
netapp hci_management_node cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*
netapp service_processor cpe:2.3:a:netapp:service_processor:-:*:*:*:*:*:*:*
netapp solidfire cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*
netapp steelstore_cloud_integrated_storage cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
netapp solidfire_baseboard_management_controller_firmware cpe:2.3:o:netapp:solidfire_baseboard_management_controller_firmware:-:*:*:*:*:*:*:*
netapp aff_baseboard_management_controller_firmware cpe:2.3:o:netapp:aff_baseboard_management_controller_firmware:-:*:*:*:*:*:*:*
netapp a320_firmware cpe:2.3:o:netapp:a320_firmware:-:*:*:*:*:*:*:*
netapp c190_firmware cpe:2.3:o:netapp:c190_firmware:-:*:*:*:*:*:*:*
netapp a220_firmware cpe:2.3:o:netapp:a220_firmware:-:*:*:*:*:*:*:*
netapp fas2720_firmware cpe:2.3:o:netapp:fas2720_firmware:-:*:*:*:*:*:*:*
netapp fas2750_firmware cpe:2.3:o:netapp:fas2750_firmware:-:*:*:*:*:*:*:*
netapp a800_firmware cpe:2.3:o:netapp:a800_firmware:-:*:*:*:*:*:*:*
netapp h300s_firmware cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
netapp h500s_firmware cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
netapp h700s_firmware cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
netapp h410s_firmware cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
netapp h410c_firmware cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
netapp h610s_firmware cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
huawei alp-al00b_firmware < 10.0.0.162\(c00e156r2p4\) cpe:2.3:o:huawei:alp-al00b_firmware:*:*:*:*:*:*:*:*
huawei alp-tl00b_firmware < 10.0.0.162\(c01e156r1p4\) cpe:2.3:o:huawei:alp-tl00b_firmware:*:*:*:*:*:*:*:*
huawei anne-al00_firmware < 9.1.0.126\(c00e126r1p7t8\) cpe:2.3:o:huawei:anne-al00_firmware:*:*:*:*:*:*:*:*
huawei ares-al00b_firmware < 9.1.0.165\(c00e165r2p5t8\) cpe:2.3:o:huawei:ares-al00b_firmware:*:*:*:*:*:*:*:*
huawei ares-al10d_firmware < 9.1.0.165\(c00e165r2p5t8\) cpe:2.3:o:huawei:ares-al10d_firmware:*:*:*:*:*:*:*:*
huawei ares-tl00chw_firmware < 8.2.0.163\(c01r2p1\) cpe:2.3:o:huawei:ares-tl00chw_firmware:*:*:*:*:*:*:*:*
huawei bla-al00b_firmware < 10.0.0.170\(c786e170r2p4\) cpe:2.3:o:huawei:bla-al00b_firmware:*:*:*:*:*:*:*:*
huawei bla-l29c_firmware < 9.1.0.300\(c432e4r1p11t8\) cpe:2.3:o:huawei:bla-l29c_firmware:*:*:*:*:*:*:*:*
huawei bla-tl00b_firmware < 10.0.0.170\(c01e170r1p4\) cpe:2.3:o:huawei:bla-tl00b_firmware:*:*:*:*:*:*:*:*
huawei barca-al00_firmware < 8.0.0.377\(c00\) cpe:2.3:o:huawei:barca-al00_firmware:*:*:*:*:*:*:*:*
huawei berkeley-l09_firmware < 9.1.0.351\(c432e5r1p13t8\) cpe:2.3:o:huawei:berkeley-l09_firmware:*:*:*:*:*:*:*:*
huawei berkeley-tl10_firmware < 9.1.0.333\(c01e333r1p1t8\) cpe:2.3:o:huawei:berkeley-tl10_firmware:*:*:*:*:*:*:*:*
huawei columbia-al00a_firmware < 8.1.0.186\(c00gt\) cpe:2.3:o:huawei:columbia-al00a_firmware:*:*:*:*:*:*:*:*
huawei columbia-l29d_firmware < 9.1.0.325\(c432e4r1p12t8\) cpe:2.3:o:huawei:columbia-l29d_firmware:*:*:*:*:*:*:*:*
huawei cornell-tl10b_firmware < 9.1.0.321\(c01e320r1p1t8\) cpe:2.3:o:huawei:cornell-tl10b_firmware:*:*:*:*:*:*:*:*
huawei duke-l09i_firmware < 9.0.1.171\(c675e6r1p5t8\) cpe:2.3:o:huawei:duke-l09i_firmware:*:*:*:*:*:*:*:*
huawei dura-al00a_firmware < 1.0.0.190\(c00\) cpe:2.3:o:huawei:dura-al00a_firmware:*:*:*:*:*:*:*:*
huawei figo-al00a_firmware < 9.1.0.130\(c00e115r2p8t8\) cpe:2.3:o:huawei:figo-al00a_firmware:*:*:*:*:*:*:*:*
huawei florida-al20b_firmware < 9.1.0.128\(c00e112r1p6t8\) cpe:2.3:o:huawei:florida-al20b_firmware:*:*:*:*:*:*:*:*
huawei florida-l03_firmware < 9.1.0.154\(c605e7r1p2t8\) cpe:2.3:o:huawei:florida-l03_firmware:*:*:*:*:*:*:*:*
huawei florida-l21_firmware < 9.1.0.154\(c605e7r1p2t8\) cpe:2.3:o:huawei:florida-l21_firmware:*:*:*:*:*:*:*:*
huawei florida-l22_firmware < 9.1.0.150\(c636e6r1p5t8\) cpe:2.3:o:huawei:florida-l22_firmware:*:*:*:*:*:*:*:*
huawei florida-tl10b_firmware < 9.1.0.128\(c01e112r1p6t8\) cpe:2.3:o:huawei:florida-tl10b_firmware:*:*:*:*:*:*:*:*
huawei mate_rs_firmware 9.1.0.321\(c786e320r1p1t8\) cpe:2.3:o:huawei:mate_rs_firmware:9.1.0.321\(c786e320r1p1t8\):*:*:*:*:*:*:*
huawei p20_firmware < 9.1.0.312\(c00e312r1p1t8\) cpe:2.3:o:huawei:p20_firmware:*:*:*:*:*:*:*:*
huawei p20_lite_firmware < 9.1.0.200\(c605e4r1p3t8\) cpe:2.3:o:huawei:p20_lite_firmware:*:*:*:*:*:*:*:*
huawei p20_lite_firmware < 9.1.0.200\(c635e5r1p1t8\) cpe:2.3:o:huawei:p20_lite_firmware:*:*:*:*:*:*:*:*
huawei p20_lite_firmware < 9.1.0.246\(c432e6r1p7t8\) cpe:2.3:o:huawei:p20_lite_firmware:*:*:*:*:*:*:*:*
huawei y9_2019_firmware < 9.1.0.297\(c605e4r1p1t8\) cpe:2.3:o:huawei:y9_2019_firmware:*:*:*:*:*:*:*:*
huawei nova_2s_firmware < 9.1.0.210\(c01e110r1p9t8\) cpe:2.3:o:huawei:nova_2s_firmware:*:*:*:*:*:*:*:*
huawei nova_3_firmware < 9.1.0.351\(c00e351r1p1t8\) cpe:2.3:o:huawei:nova_3_firmware:*:*:*:*:*:*:*:*
huawei nova_3e_firmware < 9.1.0.200\(c636e4r1p5t8\) cpe:2.3:o:huawei:nova_3e_firmware:*:*:*:*:*:*:*:*
huawei p20_lite_firmware < 9.1.0.200\(c636e4r1p5t8\) cpe:2.3:o:huawei:p20_lite_firmware:*:*:*:*:*:*:*:*
huawei p20_lite_firmware < 9.1.0.201\(c636e4r1p5t8\) cpe:2.3:o:huawei:p20_lite_firmware:*:*:*:*:*:*:*:*
huawei nova_3e_firmware < 9.1.0.201\(c636e4r1p5t8\) cpe:2.3:o:huawei:nova_3e_firmware:*:*:*:*:*:*:*:*
huawei nova_3e_firmware < 9.1.0.201\(zafc185e4r1p8t8\) cpe:2.3:o:huawei:nova_3e_firmware:*:*:*:*:*:*:*:*
huawei p20_lite_firmware < 9.1.0.201\(zafc185e4r1p8t8\) cpe:2.3:o:huawei:p20_lite_firmware:*:*:*:*:*:*:*:*
huawei honor_view_20_firmware < 10.1.0.214\(c10e5r4p3\) cpe:2.3:o:huawei:honor_view_20_firmware:*:*:*:*:*:*:*:*
huawei jakarta-al00a_firmware < 9.1.0.260\(c00e120r2p2\) cpe:2.3:o:huawei:jakarta-al00a_firmware:*:*:*:*:*:*:*:*
huawei johnson-tl00d_firmware < 9.1.0.219\(c01e18r3p2t8\) cpe:2.3:o:huawei:johnson-tl00d_firmware:*:*:*:*:*:*:*:*
huawei leland-al10b_firmware < 9.1.0.130\(c00e112r2p10t8\) cpe:2.3:o:huawei:leland-al10b_firmware:*:*:*:*:*:*:*:*
huawei leland-l21a_firmware < 9.1.0.156\(c185e5r1p5t8\) cpe:2.3:o:huawei:leland-l21a_firmware:*:*:*:*:*:*:*:*
huawei leland-l32a_firmware < 9.1.0.153\(c675e6r1p4t8\) cpe:2.3:o:huawei:leland-l32a_firmware:*:*:*:*:*:*:*:*
huawei leland-tl10b_firmware < 9.1.0.130\(c01e112r2p10t8\) cpe:2.3:o:huawei:leland-tl10b_firmware:*:*:*:*:*:*:*:*
huawei leland-tl10c_firmware < 9.1.0.130\(c01e112r2p10t8\) cpe:2.3:o:huawei:leland-tl10c_firmware:*:*:*:*:*:*:*:*
huawei lelandp-al00c_firmware < 9.1.0.130\(c00e112r2p10t8\) cpe:2.3:o:huawei:lelandp-al00c_firmware:*:*:*:*:*:*:*:*
huawei lelandp-l22c_firmware < 9.1.0.156\(c636e5r1p5t8\) cpe:2.3:o:huawei:lelandp-l22c_firmware:*:*:*:*:*:*:*:*
huawei neo-al00d_firmware < 9.1.0.321\(c786e320r1p1t8\) cpe:2.3:o:huawei:neo-al00d_firmware:*:*:*:*:*:*:*:*
huawei princeton-al10b_firmware < 10.1.0.160\(c00e160r2p11\) cpe:2.3:o:huawei:princeton-al10b_firmware:*:*:*:*:*:*:*:*
huawei rhone-al00_firmware < 8.0.0.376\(c00\) cpe:2.3:o:huawei:rhone-al00_firmware:*:*:*:*:*:*:*:*
huawei stanford-l09_firmware < 9.1.0.211\(c635e2r1p4t8\) cpe:2.3:o:huawei:stanford-l09_firmware:*:*:*:*:*:*:*:*
huawei stanford-l09s_firmware < 9.1.0.210\(c432e2r1p5t8\) cpe:2.3:o:huawei:stanford-l09s_firmware:*:*:*:*:*:*:*:*
huawei sydney-al00_firmware < 9.1.0.212\(c00e62r1p7t8\) cpe:2.3:o:huawei:sydney-al00_firmware:*:*:*:*:*:*:*:*
huawei sydney-tl00_firmware < 9.1.0.212\(c01e62r1p7t8\) cpe:2.3:o:huawei:sydney-tl00_firmware:*:*:*:*:*:*:*:*
huawei sydneym-al00_firmware < 9.1.0.212\(c00e62r1p7t8\) cpe:2.3:o:huawei:sydneym-al00_firmware:*:*:*:*:*:*:*:*
huawei tony-al00b_firmware < 10.0.0.175\(c00e59r2p11\) cpe:2.3:o:huawei:tony-al00b_firmware:*:*:*:*:*:*:*:*
huawei tony-tl00b_firmware < 10.0.0.175\(c01e59r2p11\) cpe:2.3:o:huawei:tony-tl00b_firmware:*:*:*:*:*:*:*:*

References for CVE-2019-2215

URL Tags
http://packetstormsecurity.com/files/154911/Android-Binder-Use-After-Free.html Exploit Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/155212/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html Patch Third Party Advisory VDB Entry
http://packetstormsecurity.com/files/156495/Android-Binder-Use-After-Free.html Exploit Third Party Advisory VDB Entry
http://seclists.org/fulldisclosure/2019/Oct/38 Mailing List Third Party Advisory
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20191030-01-binder-en Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/01/msg00013.html Mailing List Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html Mailing List Third Party Advisory
https://seclists.org/bugtraq/2019/Nov/11 Mailing List Patch Third Party Advisory
https://security.netapp.com/advisory/ntap-20191031-0005/ Third Party Advisory
https://source.android.com/security/bulletin/2019-10-01 Vendor Advisory
https://usn.ubuntu.com/4186-1/ Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-2215 US Government Resource
cvelogic Threat Intelligence