CVE-2018-9363

CVSS v3.1 8.4 (High)
84% Progress
CVSS v2.0 7.2 (High)
72% Progress
EPSS 0.18 % (56th)
0.18% Progress
Affected Products 4
Advisories 23

In the hidp_process_report in bluetooth, there is an integer overflow. This could lead to an out of bounds write with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-65853588 References: Upstream kernel.

Weaknesses
CWE-190
Integer Overflow or Wraparound
CWE-787
Out-of-bounds Write
CVE Status
PUBLISHED
CNA
Android (associated with Google Inc. or Open Handset Alliance)
Published Date
2018-11-06 17:29:00
(5 years ago)
Updated Date
2023-01-19 16:01:29
(20 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Google Android cpe:2.3:o:google:android:-

Configuration #2

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts
  Canonical Ubuntu Linux 18.04 cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts

Configuration #3

    CPE23 From Up To
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0

Configuration #4

    CPE23 From Up To
  Linux Kernel from 3.14 version and prior 3.16.58 version cpe:2.3:o:linux:linux_kernel >= 3.14 < 3.16.58
  Linux Kernel from 3.17 version and prior 3.18.119 version cpe:2.3:o:linux:linux_kernel >= 3.17 < 3.18.119
  Linux Kernel from 3.19 version and prior 4.4.149 version cpe:2.3:o:linux:linux_kernel >= 3.19 < 4.4.149
  Linux Kernel from 4.5 version and prior 4.9.121 version cpe:2.3:o:linux:linux_kernel >= 4.5 < 4.9.121
  Linux Kernel from 4.10 version and prior 4.14.64 version cpe:2.3:o:linux:linux_kernel >= 4.10 < 4.14.64
  Linux Kernel from 4.15 version and prior 4.17.16 version cpe:2.3:o:linux:linux_kernel >= 4.15 < 4.17.16
  Linux Kernel from 4.18 version and prior 4.18.2 version cpe:2.3:o:linux:linux_kernel >= 4.18 < 4.18.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...