CVE-2018-9547: Input Validation
In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.1 Android-9. Android ID: A-114223584.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A local attacker with low privileges can exploit it. The CVSS vector indicates no user interaction is required and no additional execution privileges are needed.
Which Android versions are affected?
The affected versions listed are Android 8.1 and Android 9.
What is the potential impact?
Successful exploitation could allow local escalation of privilege in the system server, with high impact to confidentiality, integrity, and availability.
Is a fix available?
Yes. A patch is available; the supplied references include the Android security bulletin dated 2018-12-01 and the associated source change.