CVE-2018-6241
published 2019-01-31CVE-2018-6241: NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.5th percentile
NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of privileges. Android ID: A-62540032 Severity Rating: High Version: N/A.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| nvidia_corporation | android | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2018-6241: Dragon BSP
vendor_android·2019-01-01·CVSS 7.8
CVE-2018-6241 [HIGH] CVE-2018-6241: Dragon BSP
Android Security Bulletin 2019-01-01
CVE: CVE-2018-6241
Severity: HIGH
Type: EoP
Component: Dragon BSP
References: A-62540032*
GHSA
GHSA-2x4x-73fj-7gr8: NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead
ghsa_unreviewed·2022-05-13
CVE-2018-6241 [HIGH] CWE-20 GHSA-2x4x-73fj-7gr8: NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead
NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of privileges. Android ID: A-62540032 Severity Rating: High Version: N/A.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/106476https://nvidia.custhelp.com/app/answers/detail/a_id/4804https://source.android.com/security/bulletin/2019-01-01http://www.securityfocus.com/bid/106476https://nvidia.custhelp.com/app/answers/detail/a_id/4804https://source.android.com/security/bulletin/2019-01-01
2019-01-31
Published