CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2011-1823

Known Exploited (CISA KEV)HIGH
7.8
CVSS Severity Score
EPSS Score49.1320%
EPSS Percentile92.28th
Published2011年6月9日
Last Modified2026年4月21日

Vulnerability Description

The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.

Affected Platforms (CPE)

💻
Google

Android

>= 2.0 and < 2.3.4
💻
Google

Android

= 3.0

References & Advisories

相關漏洞威脅