CVE-2011-1823

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Jun 9, 2011
Updated: Dec 20, 2024
CWE ID 190

Summary

CVE-2011-1823 is a vulnerability affecting the vold volume manager daemon in Android 3.0 and 2.x before 2.3.4. This issue allows local users to execute arbitrary code and obtain root privileges. The flaw arises from the trust placed in messages received from a PF_NETLINK socket. By exploiting a negative index that bypasses a maximum-signed integer check in the DirectVolume::handlePartitionAdded method, attackers can trigger memory corruption, ultimately leading to code execution. This vulnerability, known as Gingerbreak, poses a significant risk to Android devices running affected versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share