PT-2019-11516 · Lineageos · Lineageos
Zifnab06
·
Published
2019-07-23
·
Updated
2020-08-24
·
CVE-2019-1010221
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
LineageOS versions 16.0 and earlier
Description:
The issue concerns incorrect access control. It allows an attacker with physical access to exploit the
adb shell component by setting a specific property, enabling them to restart adb as root. This can be achieved by running the command adb shell setprop service.adb.root 1 in a normal adb shell session when adb is enabled.Recommendations:
For LineageOS versions 16.0 and earlier, consider disabling
adb access when not needed to minimize the risk of exploitation. As a temporary workaround, restrict physical access to devices until a patch is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lineageos