Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-9465

Опубликовано: 06 нояб. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.6
CVSS3: 7.8

Описание

In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-69164715 References: Upstream kernel.

РелизСтатусПримечание
bionic

not-affected

4.15.0-10.11
cosmic

not-affected

4.15.0-20.21
devel

not-affected

4.18.0-10.11
esm-infra-legacy/trusty

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
esm-infra/bionic

not-affected

4.15.0-10.11
esm-infra/xenial

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
precise/esm

ignored

end of life, was needed
trusty

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
trusty/esm

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
upstream

released

4.15~rc6

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1001.1
cosmic

not-affected

4.15.0-1007.7
devel

not-affected

4.18.0-1002.3
esm-infra-legacy/trusty

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
esm-infra/bionic

not-affected

4.15.0-1001.1
esm-infra/xenial

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
precise/esm

DNE

trusty

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
trusty/esm

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
upstream

released

4.15~rc6

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/xenial

not-affected

4.15.0-1030.31~16.04.1
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6
xenial

not-affected

4.15.0-1030.31~16.04.1

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1002.2
cosmic

not-affected

4.15.0-1009.9
devel

not-affected

4.18.0-1003.3
esm-infra-legacy/trusty

not-affected

4.15.0-1023.24~14.04.1
esm-infra/bionic

not-affected

4.15.0-1002.2
esm-infra/xenial

released

4.15.0-1013.13~16.04.2
precise/esm

DNE

trusty

not-affected

4.15.0-1023.24~14.04.1
trusty/esm

not-affected

4.15.0-1023.24~14.04.1
upstream

released

4.15~rc6

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1002.2
cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1002.2
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6
xenial

released

4.15.0-1013.13~16.04.2

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-apps/xenial

DNE

esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6
xenial

ignored

end of standard support, was needed

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-apps/xenial

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [abandoned]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [abandoned]
upstream

released

4.15~rc6
xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1001.1
cosmic

not-affected

4.15.0-1006.6
devel

not-affected

4.18.0-1002.3
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1001.1
esm-infra/xenial

released

4.15.0-1014.14~16.04.1
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.18.0-1004.5~18.04.1
cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.18.0-1004.5~18.04.1
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6
xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-apps/xenial

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [abandoned]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [abandoned]
upstream

released

4.15~rc6
xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [abandoned]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [abandoned]
upstream

released

4.15~rc6
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.18.0-13.14~18.04.1
cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.18.0-13.14~18.04.1
esm-infra/xenial

released

4.15.0-24.26~16.04.1
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6

Показывать по

РелизСтатусПримечание
bionic

not-affected

5.0.0-8.9~18.04.1
cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

5.0.0-8.9~18.04.1
esm-infra/xenial

released

4.15.0-24.26~16.04.1
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1002.2
cosmic

not-affected

4.15.0-1008.8
devel

not-affected

4.18.0-1003.3
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1002.2
esm-infra/xenial

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

precise/esm

ignored

end of life, was needed
trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [end of standard support]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [end of standard support]
upstream

released

4.15~rc6
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [end of standard support]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [end of standard support]
upstream

released

4.15~rc6
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [end of standard support]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [end of standard support]
upstream

released

4.15~rc6
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
precise/esm

DNE

trusty

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
trusty/esm

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
upstream

released

4.15~rc6
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [abandoned]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [abandoned]
upstream

released

4.15~rc6
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-apps/xenial

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [abandoned]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [abandoned]
upstream

released

4.15~rc6
xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [abandoned]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [abandoned]
upstream

released

4.15~rc6
xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1002.3
cosmic

not-affected

4.15.0-1004.5
devel

not-affected

4.15.0-1021.24
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1002.3
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6
xenial

ignored

end of standard support, was needed

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1007.9
cosmic

not-affected

4.15.0-1007.9
devel

not-affected

4.15.0-1007.9
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

4.15.0-1007.9
esm-infra/xenial

not-affected

4.15.0-1007.9~16.04.1
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6

Показывать по

РелизСтатусПримечание
bionic

not-affected

4.15.0-1006.7
cosmic

not-affected

4.15.0-1010.11
devel

not-affected

4.18.0-1005.7
esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6
xenial

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled

Показывать по

РелизСтатусПримечание
bionic

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled
cosmic

DNE

devel

not-affected

esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

released

4.15~rc6
xenial

not-affected

CONFIG_ANDROID_BINDER_IPC is disabled

Показывать по

EPSS

Процентиль: 23%
0.00075
Низкий

4.6 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
больше 7 лет назад

In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-69164715 References: Upstream kernel.

CVSS3: 7.8
nvd
больше 7 лет назад

In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-69164715 References: Upstream kernel.

CVSS3: 7.8
debian
больше 7 лет назад

In task_get_unused_fd_flags of binder.c, there is a possible memory co ...

CVSS3: 7.8
github
больше 3 лет назад

In task_get_unused_fd_flags of binder.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-69164715 References: Upstream kernel.

EPSS

Процентиль: 23%
0.00075
Низкий

4.6 Medium

CVSS2

7.8 High

CVSS3

Уязвимость CVE-2018-9465