CVE-2018-9514Use After Free in INC Android

CWE-416Use After Free4 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 94.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 2
Latest updateMay 14

Description

In sdcardfs_open of file.c, there is a possible Use After Free due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-111642636 References: N/A

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

CVEListV5google_inc/androidAndroid kernel

🔴Vulnerability Details

2
GHSA
GHSA-3p4g-jq2h-96pq: In sdcardfs_open of file2022-05-14
CVEList
CVE-2018-9514: In sdcardfs_open of file2018-10-02

📋Vendor Advisories

1
Android
CVE-2018-9514: sdcardfs2018-10-01
CVE-2018-9514 — Use After Free in Google INC Android | cvebase