CVE-2019-2054
Last modified
CVE-2019-2054 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies that allow the use of ptrace. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-119769499
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions | |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
References
- http://packetstormsecurity.com/files/153799/Kernel-Live-Patch-Security-Notice-LSN-0053-1.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlThird Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2019-05-01Vendor Advisory
- https://usn.ubuntu.com/4076-1/Third Party Advisory
- https://usn.ubuntu.com/4095-2/Third Party Advisory
- http://packetstormsecurity.com/files/153799/Kernel-Live-Patch-Security-Notice-LSN-0053-1.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.htmlThird Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2019-05-01Vendor Advisory
- https://usn.ubuntu.com/4076-1/Third Party Advisory
- https://usn.ubuntu.com/4095-2/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-2054?
How severe is CVE-2019-2054?
How do I fix CVE-2019-2054?
Are you affected by CVE-2019-2054?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
