CVE Vulnerabilities

CVE-2019-2126

Double Free

Published: Aug 20, 2019 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
8.8 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-127702368.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle7.0 (including)7.0 (including)
AndroidGoogle7.1.1 (including)7.1.1 (including)
AndroidGoogle7.1.2 (including)7.1.2 (including)
AndroidGoogle8.0 (including)8.0 (including)
AndroidGoogle8.1 (including)8.1 (including)
AndroidGoogle9.0 (including)9.0 (including)
Red Hat Enterprise Linux 8RedHatlibvpx-0:1.7.0-8.el8*
AomUbuntudisco*
AomUbuntueoan*
AomUbuntufocal*
AomUbuntugroovy*
AomUbuntuhirsute*
AomUbuntuimpish*
AomUbuntukinetic*
AomUbuntulunar*
AomUbuntutrusty*
Chromium-browserUbuntudisco*
FirefoxUbuntudisco*
GodotUbuntudevel*
GodotUbuntudisco*
GodotUbuntueoan*
GodotUbuntuesm-apps/focal*
GodotUbuntuesm-apps/jammy*
GodotUbuntuesm-apps/noble*
GodotUbuntufocal*
GodotUbuntugroovy*
GodotUbuntuhirsute*
GodotUbuntuimpish*
GodotUbuntujammy*
GodotUbuntukinetic*
GodotUbuntulunar*
GodotUbuntumantic*
GodotUbuntunoble*
GodotUbuntuoracular*
GodotUbuntuplucky*
GodotUbuntuquesting*
GodotUbuntutrusty*
LibvpxUbuntubionic*
LibvpxUbuntudisco*
LibvpxUbuntuesm-infra/bionic*
LibvpxUbuntutrusty*
Qtwebengine-opensource-srcUbuntubionic*
Qtwebengine-opensource-srcUbuntudisco*
Qtwebengine-opensource-srcUbuntueoan*
Qtwebengine-opensource-srcUbuntufocal*
Qtwebengine-opensource-srcUbuntugroovy*
Qtwebengine-opensource-srcUbuntuhirsute*
Qtwebengine-opensource-srcUbuntuimpish*
Qtwebengine-opensource-srcUbuntukinetic*
Qtwebengine-opensource-srcUbuntulunar*
Qtwebengine-opensource-srcUbuntumantic*
Qtwebengine-opensource-srcUbuntuoracular*
Qtwebengine-opensource-srcUbuntuplucky*
Qtwebengine-opensource-srcUbuntutrusty*
ThunderbirdUbuntudisco*

Potential Mitigations

References