BINDER_LOOPER_STATE_POLL introduced in

Oct 14, 2019 10:21

1b77e9dcc3da9359f5936a7a4a0b5b6585c5e37eAuthor: Martijn Coenen 2017-08-31 11:04:18 ( Read more... )

Leave a comment

Comments 1

scdm May 14 2020, 01:50:38 UTC
source

CVE-2019-2215 made some headlines because of P0.
On the other hand something like CVE-2019-15239 went unnoticed.
First reported and fixed in early 2018
The bug was present in all 4.4/4.9 android kernels for over a year after the 4.14 upstream fix

Mid last year a cve was finally assigned and the fix backported to 4.4/4.9 because syzkaller kept triggering the bug
The bug can even be exploited using the same iovec refill technique used in the P0 post

Reply


Leave a comment

Up