CVE-2018-21054: Integer Overflow
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0) except MSM8939, N(7.1) except MSM8996 SDM6xx/M6737T software. There is an integer underflow with a resultant buffer overflow in eCryptFS. The Samsung ID is SVE-2017-11857 (September 2018).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-21054?
The severity of CVE-2018-21054 is critical with a rating of 9.8.
Which devices are affected by CVE-2018-21054?
Samsung mobile devices with M(6.0), N(7.x), and O(8.x) are affected, except Exynos9610/9820, MSM8909 SC77xx/9830, Exynos3470/5420, and MSM8939.
What is the vulnerability description of CVE-2018-21054?
CVE-2018-21054 is an integer underflow vulnerability that leads to a buffer overflow on Samsung mobile devices running M(6.0), N(7.x), and O(8.x), except for specific device models and software versions.
How can I fix CVE-2018-21054?
Apply the security update provided by Samsung to fix CVE-2018-21054. More information can be found at the reference link.
What is the Common Weakness Enumeration (CWE) for CVE-2018-21054?
CVE-2018-21054 is associated with CWE-119 and CWE-190.