CVE-2019-2201: Critical severity Google Android vulnerability
In generatejsimdyccrgbconvertneon of jsimdarm64neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-2201?
CVE-2019-2201 is a vulnerability in the jsimd_arm64_neon.S file, which could lead to remote code execution in an unprivileged process.
How severe is CVE-2019-2201?
CVE-2019-2201 has a severity rating of 7.8 (critical).
Which software and versions are affected by CVE-2019-2201?
Google Android versions 8.0, 8.1, 9.0, and 10.0, as well as Debian/libjpeg-turbo versions 1:1.5.2-2+deb10u1, 1:2.0.6-4, and 1:2.1.5-2, and Ubuntu/libjpeg-turbo versions 1.5.2-0ubuntu5.18.04.3, 2.0.1-0ubuntu2.2, and 1.4.2-0ubuntu3.3, are affected by CVE-2019-2201.
How can I fix CVE-2019-2201 on my Android device?
To fix CVE-2019-2201 on your Android device, you should update to the latest available security patch provided by Google.
How can I fix CVE-2019-2201 on my Debian or Ubuntu system?
To fix CVE-2019-2201 on your Debian system, you should update the libjpeg-turbo package to version 1:1.5.2-2+deb10u1, 1:2.0.6-4, or 1:2.1.5-2. For Ubuntu systems, update the libjpeg-turbo package to version 1.5.2-0ubuntu5.18.04.3, 2.0.1-0ubuntu2.2, or 1.4.2-0ubuntu3.3, depending on your version.