First published: Tue Oct 16 2018(Updated: )
kernel/omap/drivers/mfd/twl6030-gpadc.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/twl6030-gpadc with the command 24832 and cause a kernel crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Fire OS | =4.5.5.3 | |
Amazon Kindle Fire HD | =3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11025 is high with a severity value of 7.5.
Amazon Fire OS 4.5.5.3 and Amazon Kindle Fire HD 3 are affected by CVE-2018-11025.
An attacker can exploit CVE-2018-11025 by injecting a crafted argument via the ioctl command on the device /dev/twl6030-gpadc with the specific command number.
No, Amazon Kindle Fire HD 3 is not vulnerable to CVE-2018-11025.
Yes, you can find more information about CVE-2018-11025 at the following link: [GitHub Advisory](https://github.com/datadancer/HIAFuzz/blob/master/CVE-Advisory.md).