CVE-2018-9518: High severity Google Android vulnerability
In nfcllcpbuildsdreqtlv of llcpcommands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-73083945.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.176-1Fixed in 6.1.187-1Fixed in 6.12.107-1Fixed in 7.1.13-1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9518?
The severity of CVE-2018-9518 is high.
How does CVE-2018-9518 work?
CVE-2018-9518 works by exploiting a missing bounds check in nfc_llcp_build_sdreq_tlv of llcp_commands.c, leading to an out of bounds write.
What is the affected software for CVE-2018-9518?
The affected software for CVE-2018-9518 includes Android kernel versions 4.16~ and below.
Is user interaction required for exploitation of CVE-2018-9518?
No, user interaction is not needed for exploitation of CVE-2018-9518.
How can I fix CVE-2018-9518?
To fix CVE-2018-9518, update your Android device to a version that includes a patched kernel, as specified by the vendor or distribution.