HIGH
In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check
Published Nov 19, 2024
7.5
HIGHCVSS 3.1
EPSS 0.30%
Description
In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected products
-
- Version 7StatusaffectedConstraints-
- Version 8StatusaffectedConstraints-
- Version 8.1StatusaffectedConstraints-
- Version nyc-mr1-devStatusaffectedConstraints-
- Version nyc-mr2-devStatusaffectedConstraints-
- Version
-
- Version 7StatusaffectedConstraints-
- Version 8StatusaffectedConstraints-
- Version 8.1StatusaffectedConstraints-
- Version nyc-mr1-devStatusaffectedConstraints-
- Version nyc-mr2-devStatusaffectedConstraints-
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://source.android.com/security/bulletin/2018-09-01 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://source.android.com/security/bulletin/2018-09-01 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Nov 19, 2024
Updated Nov 21, 2024
Reserved Apr 5, 2018
Link CVE-2018-9456
CISA Vulnrichment
Updated Nov 21, 2024