CVE-2019-5282: Double Free
Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.202(C185E2R1P12) have a double free vulnerability. An attacker tricks the user into installing a malicious application, which frees on the same memory address twice. Successful exploit could result in malicious code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5282?
CVE-2019-5282 is a vulnerability in the Bastet module of some Huawei smartphones with versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Emily-TL00B 9.0.0.182(C01E82R1P21), Emily-L09C 9.0.0.203(C432E7R1P11), Emily-L29C 9.0.0.203(C432E7R1P11).
What is the severity rating of CVE-2019-5282?
The severity rating of CVE-2019-5282 is 7.8 (High).
Which Huawei smartphones are affected by CVE-2019-5282?
Huawei smartphones with versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Emily-TL00B 9.0.0.182(C01E82R1P21), Emily-L09C 9.0.0.203(C432E7R1P11), Emily-L29C 9.0.0.203(C432E7R1P11) are affected by CVE-2019-5282.
How can I fix CVE-2019-5282?
To fix CVE-2019-5282, update your Huawei smartphone to versions Emily-AL00A 9.0.0.182(C00E82R1P21), Emily-TL00B 9.0.0.182(C01E82R1P21), Emily-L09C 9.0.0.203(C432E7R1P11), Emily-L29C 9.0.0.203(C432E7R1P11) or later.
Where can I find more information about CVE-2019-5282?
More information about CVE-2019-5282 can be found on the Huawei website at http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190220-01-smartphone-en.