CVE-2018-19939: Null Pointer Dereference
The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtpreadColor in drivers/input/touchscreen/gt917d/gt9xx.c.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19939?
CVE-2018-19939 is classified as a low-severity vulnerability due to the nature of the NULL pointer dereference.
How do I fix CVE-2018-19939?
To fix CVE-2018-19939, ensure that the affected devices are updated to a firmware version released after August 27, 2018.
What devices are affected by CVE-2018-19939?
CVE-2018-19939 affects the Mi A2 Lite and Redmi 6 devices running specific firmware versions up to August 27, 2018.
What exploit does CVE-2018-19939 introduce?
CVE-2018-19939 introduces a vulnerability that could potentially lead to a denial of service due to the NULL pointer dereference.
Is CVE-2018-19939 remotely exploitable?
CVE-2018-19939 is not considered remotely exploitable as it requires local access to the affected device.