PT-2019-16218 · Google+7 · Android+7

Published

2019-08-20

·

Updated

2025-06-18

·

CVE-2019-2126

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Android versions 7.0 through 9
Description The issue is related to a possible double free in the ParseContentEncodingEntry function of mkvparser.cc due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is required for exploitation.
Recommendations For Android versions 7.0 through 9, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Double Free

Weakness Enumeration

Related Identifiers

ALSA-2020:4629
CESA-2020_4629
CVE-2019-2126
MGASA-2019-0369
OPENSUSE-SU-2020:0105-1
OPENSUSE-SU-2020_0105-1
OPENSUSE-SU-2024:11010-1
RHSA-2020:4629
RHSA-2020_4629
RLSA-2020:4629
SUSE-SU-2020:0143-1
SUSE-SU-2020_0143-1
USN-4199-1
USN-7579-1

Affected Products

Almalinux
Android
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu