PT-2018-10832 · Mozilla+3 · Firefox Os+3

Published

2018-09-18

·

Updated

2018-11-09

·

CVE-2018-11818

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Android for MSM (affected versions not specified) Firefox OS for MSM (affected versions not specified) QRD Android (affected versions not specified)
Description The issue arises from the way LUT configuration is passed from userspace to the driver via ioctl in the linux kernel, used by all android releases from CAF. A race condition can occur when there are simultaneous updates from userspace while kernel drivers are updating LUT registers.
Recommendations For Android for MSM, consider restricting access to the ioctl until a proper synchronization mechanism is implemented to prevent the race condition. For Firefox OS for MSM, avoid simultaneous updates from userspace while kernel drivers are updating LUT registers as a temporary workaround. For QRD Android, implement a locking mechanism to ensure exclusive access to LUT registers during updates to prevent the race condition. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Race Condition

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11818

Affected Products

Android
Firefox Os
Linux Kernel
Qrd Android