CVE-2019-8413: Null Pointer Dereference
Published Feb 17, 2019
·Updated
On Xiaomi MIX 2 devices with the 4.4.78 kernel, a NULL pointer dereference in the ioctl interface of the device file /dev/elliptic1 or /dev/elliptic0 causes a system crash via IOCTL 0x4008c575 (aka decimal 1074316661).
Affected Software
4 affected components
Mi Mi Mix 2 Firmware=4.4.78
Mi mi MIX 2
All of the following
Mi Mi Mix 2 Firmware=4.4.78
Mi mi MIX 2
Event History
Feb 17, 2019
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-8413?
CVE-2019-8413 has a high severity due to its potential to cause system crashes on affected Xiaomi MIX 2 devices.
2
How do I fix CVE-2019-8413?
To fix CVE-2019-8413, users should update the device firmware to a version higher than 4.4.78.
3
Which devices are affected by CVE-2019-8413?
CVE-2019-8413 specifically affects Xiaomi MIX 2 devices running the 4.4.78 kernel.
4
What is the cause of CVE-2019-8413?
CVE-2019-8413 is caused by a NULL pointer dereference in the ioctl interface of the device files /dev/elliptic1 or /dev/elliptic0.
5
What is the impact of exploiting CVE-2019-8413?
Exploiting CVE-2019-8413 can lead to a system crash on vulnerable Xiaomi MIX 2 devices.