CVE-2018-9568: Incorrect Type Cast
A possible memory corruption due to a type confusion was found in the Linux kernel in the skclonelock() function in the net/core/sock.c. A possibility of local escalation of privileges cannot be fully ruled out for a local unprivileged attacker.
References:
https://source.android.com/security/bulletin/2018-12-01.html#kernel-components
An upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9d538fa60bad4f7b23193c89e843797a1cf71ef3
Other sources
In skclonelock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References: Upstream kernel.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.262-1Fixed in 6.1.176-1Fixed in 6.1.180-1Fixed in 6.12.94-1Fixed in 6.12.101-1Fixed in 7.1.7-1Fixed in 7.1.8-1 - Upgrade
Upgrade
Android kernelto a version that resolves this vulnerability.Patch A-113509306
Event History
Frequently Asked Questions
What is the vulnerability ID for this memory corruption vulnerability?
The vulnerability ID for this memory corruption vulnerability is CVE-2018-9568.
What is the severity level of CVE-2018-9568?
The severity level of CVE-2018-9568 is high.
What is the affected software for CVE-2018-9568?
The affected software for CVE-2018-9568 is Android kernel.
Is user interaction required for exploitation of CVE-2018-9568?
No, user interaction is not needed for exploitation of CVE-2018-9568.
How can I fix CVE-2018-9568?
To fix CVE-2018-9568, you should update your Android kernel to version 4.14~ or higher.