CWE
190 119
Advisory Published
Updated

CVE-2018-21054: Integer Overflow

First published: Wed Apr 08 2020(Updated: )

An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0) except MSM8939, N(7.1) except MSM8996 SDM6xx/M6737T software. There is an integer underflow with a resultant buffer overflow in eCryptFS. The Samsung ID is SVE-2017-11857 (September 2018).

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Google Android=6.0
Google Android=7.0
Google Android=7.1.0
Google Android=7.1.1
Google Android=7.1.2
Google Android=8.0
Google Android=8.1
Samsung Exynos 9610
Samsung Exynos 9820
Qualcomm Msm8909
Qualcomm Msm9830
Samsung Exynos 3470
Samsung Exynos 5420
Unisoc Sc7715
Unisoc Sc7730
Unisoc Sc7731
Google Android
Google Android=7.1
Mediatek M6737t
Google Android
Qualcomm Sdm6xx

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2018-21054?

    The severity of CVE-2018-21054 is critical with a rating of 9.8.

  • Which devices are affected by CVE-2018-21054?

    Samsung mobile devices with M(6.0), N(7.x), and O(8.x) are affected, except Exynos9610/9820, MSM8909 SC77xx/9830, Exynos3470/5420, and MSM8939.

  • What is the vulnerability description of CVE-2018-21054?

    CVE-2018-21054 is an integer underflow vulnerability that leads to a buffer overflow on Samsung mobile devices running M(6.0), N(7.x), and O(8.x), except for specific device models and software versions.

  • How can I fix CVE-2018-21054?

    Apply the security update provided by Samsung to fix CVE-2018-21054. More information can be found at the reference link.

  • What is the Common Weakness Enumeration (CWE) for CVE-2018-21054?

    CVE-2018-21054 is associated with CWE-119 and CWE-190.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203