PT-2018-19024 · Google · Android Kernel
Published
2018-12-07
·
Updated
2019-01-08
·
CVE-2018-9519
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android kernel
Description
The issue is related to a possible out of bounds write due to a race condition in the
easelcomm hw build scatterlist function. This could lead to local escalation of privilege, with System privileges required for exploitation. User interaction is not needed for exploitation.Recommendations
For Android kernel, consider applying a patch to fix the race condition in the
easelcomm hw build scatterlist function to prevent out of bounds write and potential local escalation of privilege.Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android Kernel