cbcvebase.
CVE-2018-9415
published 2018-11-06

CVE-2018-9415: In driver_override_store and driver_override_show of bus.c, there is a possible double free due to improper locking. This could lead to local escalation of…

high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
In driver_override_store and driver_override_show of bus.c, there is a possible double free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-69129004 References: Upstream kernel.

Affected

9 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 4.16.12-1 (bookworm)linux 4.16.12-1 (bookworm)
google_incandroid
linuxlinux_kernel>= 0 < 4.16.12-14.16.12-1
linuxlinux_kernel>= 0 < 4.16.12-14.16.12-1
linuxlinux_kernel>= 0 < 4.16.12-14.16.12-1
linuxlinux_kernel>= 0 < 4.16.12-14.16.12-1
linuxlinux_kernel>= 0 < 4.15.0-33.364.15.0-33.36

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH