Does that mean any android app can use ndk native code execution to become root? Does selinux help here?
Considering that it's rare to get kernel (or any) updates on non-flagship phones, it seems likely. Backporting an old kernel should be possible, but the only indicator is the system update changelog that explicitly mentions it, I rarely see CVEs mentioned in changelogs on any smartphone. A tool to test the vulnerability is the only way. Any compromised app on the Play store or external can get root access instantly,…
How the cluster f*k of the Android update situation Google has allowed this to happen really needs a regulator to step in.
Planned obsolescence is supposed to be illegal in Europe.