CVE-2018-21040: Use After Free
Published Apr 8, 2020
·Updated
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is a race condition with a resultant use-after-free in the g2d driver. The Samsung ID is SVE-2018-12959 (December 2018).
Affected Software
4 affected components
Google Android=8.0
Google Android=8.1
Google Android=9.0
Samsung Exynos 9810
Event History
Apr 8, 2020
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-21040.
2
What is the severity of CVE-2018-21040?
The severity of CVE-2018-21040 is high with a severity value of 8.1.
3
Which devices are affected by CVE-2018-21040?
Samsung mobile devices with O(8.x) and P(9.0) software (Exynos 9810 chipsets) are affected.
4
What is the race condition in the g2d driver?
The race condition in the g2d driver is a race condition with a resultant use-after-free vulnerability.
5
How can I fix CVE-2018-21040?
To fix CVE-2018-21040, update your Samsung mobile device with the latest security update from Samsung.