Early Access — Mondoo Vulnerability Intelligence is currently in preview.
In binder_transaction of binder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-136210786References: Upstream kernel
5.3.0-18.195.3.0-24.265.4.0-9.124.2.0-16.194.13.0-16.194.4.0-1001.105.3.0-1003.35.3.0-1008.95.3.0-1009.105.3.0-1010.115.4.0-1005.54.15.0-1001.15.0.0-1021.24~18.04.15.0.0-1022.25~18.04.15.0.0-1023.26~18.04.14.15.0-1030.31~16.04.14.11.0-1009.95.3.0-1003.35.3.0-1008.95.3.0-1009.105.4.0-1006.6Exploitability
AV:LAC:LPR:LUI:NScope
S:UImpact
C:HI:HA:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H