CVE-2018-11019: High severity amazon fire os vulnerability
Published Oct 16, 2018
·Updated
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3221773726 and cause a kernel crash.
Affected Software
2 affected components
Amazon Fire OS=4.5.5.3
Amazon Kindle Fire HD=3
Event History
Oct 16, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11019?
The severity of CVE-2018-11019 is high with a score of 7.5.
2
How does CVE-2018-11019 affect Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3?
CVE-2018-11019 allows attackers to inject a crafted argument via an ioctl on device /dev/gcioctl and cause a kernel crash.
3
How can the vulnerability in CVE-2018-11019 be exploited?
The vulnerability in CVE-2018-11019 can be exploited by injecting a crafted argument via an ioctl on device /dev/gcioctl.
4
Are Amazon Kindle Fire HD devices vulnerable to CVE-2018-11019?
Amazon Kindle Fire HD(3rd) with Fire OS 4.5.5.3 is affected by CVE-2018-11019.
5
Is there a fix available for CVE-2018-11019?
Please refer to the provided references for information on available fixes for CVE-2018-11019.