First published: Wed Apr 08 2020(Updated: )
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0) except MSM8939, N(7.1) except MSM8996 SDM6xx/M6737T software. There is an integer underflow with a resultant buffer overflow in eCryptFS. The Samsung ID is SVE-2017-11857 (September 2018).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =6.0 | |
Google Android | =7.0 | |
Google Android | =7.1.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 | |
Google Android | =8.0 | |
Google Android | =8.1 | |
Samsung Exynos 9610 | ||
Samsung Exynos 9820 | ||
Qualcomm Msm8909 | ||
Qualcomm Msm9830 | ||
Samsung Exynos 3470 | ||
Samsung Exynos 5420 | ||
Unisoc Sc7715 | ||
Unisoc Sc7730 | ||
Unisoc Sc7731 | ||
Google Android | ||
Google Android | =7.1 | |
Mediatek M6737t | ||
Google Android | ||
Qualcomm Sdm6xx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-21054 is critical with a rating of 9.8.
Samsung mobile devices with M(6.0), N(7.x), and O(8.x) are affected, except Exynos9610/9820, MSM8909 SC77xx/9830, Exynos3470/5420, and MSM8939.
CVE-2018-21054 is an integer underflow vulnerability that leads to a buffer overflow on Samsung mobile devices running M(6.0), N(7.x), and O(8.x), except for specific device models and software versions.
Apply the security update provided by Samsung to fix CVE-2018-21054. More information can be found at the reference link.
CVE-2018-21054 is associated with CWE-119 and CWE-190.