First published: Wed Apr 08 2020(Updated: )
An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition with a resultant double free in vnswap_init_backing_storage. The Samsung ID is SVE-2017-11177 (February 2018).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | =5.0 | |
Google Android | =5.0.1 | |
Google Android | =5.0.2 | |
Google Android | =5.1 | |
Google Android | =5.1.0 | |
Google Android | =5.1.1 | |
Google Android | =6.0 | |
Google Android | =7.0 | |
Google Android | =7.1.0 | |
Google Android | =7.1.1 | |
Google Android | =7.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21086 has a moderate severity due to the potential for a race condition leading to a double free in affected devices.
To fix CVE-2018-21086, you should update your Samsung mobile device to the latest security patch provided by the manufacturer.
CVE-2018-21086 affects various Samsung mobile devices running Android versions Lollipop (5.x), Marshmallow (6.0), and Nougat (7.x).
In the context of CVE-2018-21086, a race condition occurs when two processes attempt to access and modify shared resource memory simultaneously, potentially leading to instability.
CVE-2018-21086 is not explicitly stated to be remotely exploitable, but the vulnerability could potentially allow an attacker to affect device memory management.