PT-2020-8730 · Samsung · Samsung Mobile Devices With N(7.X)+2

Published

2020-04-08

·

Updated

2020-04-09

·

CVE-2018-21086

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung mobile devices with L(5.x) software Samsung mobile devices with M(6.0) software Samsung mobile devices with N(7.x) software
Description The issue is related to a race condition with a resultant double free in vnswap init backing storage. This condition can lead to unintended behavior.
Recommendations For Samsung mobile devices with L(5.x) software, update to a version that fixes the issue. For Samsung mobile devices with M(6.0) software, update to a version that fixes the issue. For Samsung mobile devices with N(7.x) software, update to a version that fixes the issue. As a temporary workaround, consider restricting access to the vnswap init backing storage function until a patch is available.

Fix

Race Condition

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-21086

Affected Products

Samsung Mobile Devices With L(5.X)
Samsung Mobile Devices With M(6.0)
Samsung Mobile Devices With N(7.X)