Description
In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-200688826References: Upstream kernel
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2940-1 | linux security update |
Debian DLA |
DLA-2941-1 | linux-4.19 security update |
Debian DSA |
DSA-5096-1 | linux security update |
EUVD |
EUVD-2021-26043 | In several functions of binder.c, there is a possible way to represent the wrong domain to SELinux due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-200688826References: Upstream kernel |
References
History
No history.
Status: PUBLISHED
Assigner: google_android
Published:
Updated: 2024-08-04T02:13:37.689Z
Reserved: 2021-08-23T00:00:00.000Z
Link: CVE-2021-39686
No data.
Status : Modified
Published: 2022-03-16T15:15:10.417
Modified: 2024-11-21T06:20:00.463
Link: CVE-2021-39686
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD