CVE-2019-1999
Estado: ModificadaAlta (7.8)—💥 Exploit
En binder_alloc_free_page en binder_alloc.c, existe una posible doble liberación (double free) debido a un bloqueo incorrecto. Esto podría llevar a un escalado de privilegios local en el kernel sin necesitar privilegios de ejecución adicionales. No se necesita interacción del usuario para explotarlo. Producto: Android. Versiones: Android kernel. Android ID: A-120025196.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.81%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 9/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Android - binder Use-After-Free of VMA via race Between reclaim and munmap (12/2/2019)
Tecnologías afectadas (3)
CWE
- CWE-415
Referencias
- http://www.securityfocus.com/bid/106851
- https://seclists.org/bugtraq/2019/Aug/13
- https://source.android.com/security/bulletin/2019-02-01
- https://usn.ubuntu.com/3979-1/
- https://www.debian.org/security/2019/dsa-4495
- https://www.exploit-db.com/exploits/46357/
- http://www.securityfocus.com/bid/106851
- https://seclists.org/bugtraq/2019/Aug/13
- https://source.android.com/security/bulletin/2019-02-01
- https://usn.ubuntu.com/3979-1/
- https://www.debian.org/security/2019/dsa-4495
- https://www.exploit-db.com/exploits/46357/
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-1999",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "security@android.com",
"affectedData": [
{
"vendor": "Android",
"product": "Android",
"versions": [
{
"status": "affected",
"version": "Android kernel"
}
]
}
]
}
],
"published": "2019-02-28T17:29:00.990",
"references": [
{
"url": "http://www.securityfocus.com/bid/106851",
"tags": [
"Broken Link"
],
"source": "security@android.com"
},
{
"url": "https://seclists.org/bugtraq/2019/Aug/13",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "security@android.com"
},
{
"url": "https://source.android.com/security/bulletin/2019-02-01",
"tags": [
"Vendor Advisory"
],
"source": "security@android.com"
},
{
"url": "https://usn.ubuntu.com/3979-1/",
"tags": [
"Third Party Advisory"
],
"source": "security@android.com"
},
{
"url": "https://www.debian.org/security/2019/dsa-4495",
"tags": [
"Third Party Advisory"
],
"source": "security@android.com"
},
{
"url": "https://www.exploit-db.com/exploits/46357/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "security@android.com"
},
{
"url": "http://www.securityfocus.com/bid/106851",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://seclists.org/bugtraq/2019/Aug/13",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://source.android.com/security/bulletin/2019-02-01",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://usn.ubuntu.com/3979-1/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.debian.org/security/2019/dsa-4495",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/46357/",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-415"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-120025196."
},
{
"lang": "es",
"value": "En binder_alloc_free_page en binder_alloc.c, existe una posible doble liberación (double free) debido a un bloqueo incorrecto. Esto podría llevar a un escalado de privilegios local en el kernel sin necesitar privilegios de ejecución adicionales. No se necesita interacción del usuario para explotarlo. Producto: Android. Versiones: Android kernel. Android ID: A-120025196."
}
],
"lastModified": "2026-06-17T02:29:48.927",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:google:android:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DEECE5FC-CACF-4496-A3E7-164736409252"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD783B0C-9246-47D9-A937-6144FE8BFF0F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@android.com"
}