CVE-2018-9426: High severity android vulnerability
In RsaKeyPairGenerator::getNumberOfIterations of RSAKeyPairGenerator.java, an incorrect implementation could cause weak RSA key pairs being generated. This could lead to crypto vulnerability with no additional execution privileges needed. User interaction is not needed for exploitation. Bulletin Fix: The fix is designed to correctly implement the key generation according to FIPS standard.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9426?
CVE-2018-9426 has a severity rating of moderate due to the potential generation of weak RSA key pairs.
How do I fix CVE-2018-9426?
To fix CVE-2018-9426, users should update their Android devices to the latest available version that addresses this vulnerability.
Which versions of Android are affected by CVE-2018-9426?
CVE-2018-9426 affects Android versions 7.0, 7.1.1, 7.1.2, 8.0, and 8.1.
What could happen if CVE-2018-9426 is exploited?
Exploitation of CVE-2018-9426 could lead to the use of weak RSA key pairs, compromising cryptographic security.
Is user interaction required for exploiting CVE-2018-9426?
No, user interaction is not required for the exploitation of CVE-2018-9426.