CVE-2018-9589: Medium severity Google Android vulnerability
In ieee80211rxwnmsleepreq of wnmap.c in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the wifi driver with no additional execution privileges needed. User interaction is not needed for exploitation. Android ID: A-111893132.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9589?
CVE-2018-9589 is classified as a moderate severity vulnerability due to the potential for local information disclosure.
How do I fix CVE-2018-9589?
Fixing CVE-2018-9589 requires upgrading to a version of Android that has addressed this vulnerability, specifically versions 9.0 and above.
What types of devices are affected by CVE-2018-9589?
CVE-2018-9589 affects devices running Android versions 7.0, 7.1.1, 7.1.2, 8.0, 8.1, and 9.0.
What does CVE-2018-9589 exploit in Android?
CVE-2018-9589 exploits a potential out of bounds read caused by a missing bounds check in the wifi driver.
What could an attacker gain from exploiting CVE-2018-9589?
Exploiting CVE-2018-9589 could allow an attacker to disclose sensitive local information.