Vulnerability record

CVE-2011-1823

Android OS Privilege Escalation Vulnerability

Severity: HighExploitation: Exploitation confirmedCISA KEV
What should I do?

This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run Android OS, fix it now.

CISA required action: Apply updates per vendor instructions.

US federal civilian agencies must remediate by Sep 29, 2022.

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations and CISA's required action, limit exposure of affected systems, and watch this record for a patch.

Description

The vold volume manager daemon on Android 3.0 and 2.x before 2.3.4 trusts messages that are received from a PF_NETLINK socket, which allows local users to execute arbitrary code and gain root privileges via a negative index that bypasses a maximum-only signed integer check in the DirectVolume::handlePartitionAdded method, which triggers memory corruption, as demonstrated by Gingerbreak.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Affected products

Products affected by this vulnerability, with versions and the source of each entry
ProductVendorAffected versionsFixed inSource
AndroidGoogle>= 2.0, < 2.3.4; 3.02.3.4NVD
Android OSAndroid——KEV

Sources: NVD = NIST National Vulnerability Database; KEV = CISA Known Exploited Vulnerabilities catalog.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdateKEV

    CVE-2011-1823 scored CVSS 7.8: Android Android OS, Android OS Privilege Escalation Vulnerability

    CISA lists this as exploited in the wild. Unpatched Android OS systems are exposed to active attacks now.

    Basis: NIST National Vulnerability Database

1 earlier event is available with a subscription. See plans.

Coverage

We have not published a story about this vulnerability yet.

References

  • android.googlesource.com https://android.googlesource.com/platform/system/vold/+/c51920c82463b240e2be0430849837d6fdc5352e
  • nvd.nist.gov https://nvd.nist.gov/vuln/detail/CVE-2011-1823
  • android.git.kernel.org http://android.git.kernel.org/?p=platform/system/core.git%3Ba=commit%3Bh=b620a0b1c7ae486e979826200e8e441605b0a…
  • android.git.kernel.org http://android.git.kernel.org/?p=platform/system/netd.git%3Ba=commit%3Bh=79b579c92afc08ab12c0a5788d61f2dd29348…
  • android.git.kernel.org http://android.git.kernel.org/?p=platform/system/vold.git%3Ba=commit%3Bh=c51920c82463b240e2be0430849837d6fdc53…
  • androidcommunity.com http://androidcommunity.com/gingerbreak-root-for-gingerbread-app-20110421/
  • c-skills.blogspot.com http://c-skills.blogspot.com/2011/04/yummy-yummy-gingerbreak.html
  • forum.xda-developers.com http://forum.xda-developers.com/showthread.php?t=1044765
  • androidpolice.com http://www.androidpolice.com/2011/05/03/google-patches-gingerbreak-exploit-but-dont-worry-we-still-have-root-f…
  • xorl.wordpress.com http://xorl.wordpress.com/2011/04/28/android-vold-mpartminors-signedness-issue/
  • exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/67977
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-1823