PT-2019-16044 · Google · Android Kernel

Published

2019-02-28

·

Updated

2021-07-21

·

CVE-2019-2001

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android kernel
Description The issue concerns the permissions on the /proc/iomem file, which were world-readable. This could lead to local information disclosure without requiring additional execution privileges. User interaction is not necessary for exploitation.
Recommendations For Android kernel, consider restricting access to the /proc/iomem file to prevent local information disclosure until a patch is available.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-2001

Affected Products

Android Kernel