First published: Mon Mar 02 2020(Updated: )
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
Credit: security@android.com security@android.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
All of | ||
Huawei Berkeley-l09 Firmware | <10.0.0.177\(c10e3r1p4\) | |
Huawei Berkeley-l09 | ||
All of | ||
Huawei Columbia-al10b Firmware | <10.0.0.178\(c00e178r1p4\) | |
Huawei Columbia-al10b | ||
All of | ||
Huawei Columbia-l29d Firmware | <10.0.0.177\(c10e4r1p4\) | |
Huawei Columbia-l29d | ||
All of | ||
Huawei Columbia-tl00b Firmware | <10.0.0.178\(c01e178r1p4\) | |
Huawei Columbia-tl00b | ||
All of | ||
Huawei Columbia-tl00d Firmware | <10.0.0.178\(c01e178r1p4\) | |
Huawei Columbia-tl00d | ||
All of | ||
Huawei Cornell-al00a Firmware | <9.1.0.340\(c00e333r1p1t8\) | |
Huawei Cornell-al00a | ||
All of | ||
Huawei Cornell-tl10b Firmware | <9.1.0.340\(c01e333r1p1t8\) | |
Huawei Cornell-tl10b | ||
All of | ||
Huawei Dura-al00a Firmware | <1.0.0.190\(c00\) | |
Huawei Dura-al00a | ||
All of | ||
Huawei Honor 20 Pro Firmware | <10.0.0.194\(c636e3r3p1\) | |
Huawei HONOR 20 PRO | ||
All of | ||
Huawei Y6 2019 Firmware | <9.1.0.290\(c185e5r4p1\) | |
Huawei Y6 2019 | ||
All of | ||
Huawei Nova 3 Firmware | <9.1.0.338\(c00e333r1p1t8\) | |
Huawei Nova 3 | ||
All of | ||
Huawei Nova 4 Firmware | <10.0.0.160\(c01e32r2p4\) | |
HUAWEI nova 4 | ||
All of | ||
Huawei Honor 8a Firmware | <9.1.0.291\(c185e3r4p1\) | |
Huawei Honor 8a | ||
All of | ||
Huawei Honor View 20 Firmware | <10.0.0.198\(c432e10r3p4\) | |
Huawei Honor View 20 | ||
All of | ||
Huawei Jakarta-al00a Firmware | <9.1.0.251\(c00e106r2p2\) | |
Huawei Jakarta-al00a | ||
All of | ||
Huawei Katyusha-al00a Firmware | <9.1.0.146\(c00e131r2p2\) | |
Huawei Katyusha-al00a | ||
All of | ||
Huawei Katyusha-al10a Firmware | <9.1.0.160\(c00e150r1p7\) | |
Huawei Katyusha-al10a | ||
All of | ||
Huawei Madrid-al00a Firmware | <9.1.0.261\(c00e120r4p1\) | |
Huawei Madrid-al00a | ||
All of | ||
Huawei Paris-l29b Firmware | <9.1.0.380\(c636e1r1p3t8\) | |
Huawei Paris-l29b | ||
All of | ||
Huawei Princeton-al10b Firmware | <10.0.0.194\(c00e61r4p11\) | |
Huawei Princeton-al10b | ||
All of | ||
Huawei Sydney-al00 Firmware | <9.1.0.237\(c00e80r1p7t8\) | |
Huawei Sydney-al00 | ||
All of | ||
Huawei Sydney-tl00 Firmware | <9.1.0.237\(c01e80r1p7t8\) | |
Huawei Sydney-tl00 | ||
All of | ||
Huawei Sydneym-al00 Firmware | <10.0.0.159\(c00e64r1p5\) | |
Huawei Sydneym-al00 | ||
All of | ||
Huawei Tony-al00b Firmware | <10.1.0.137\(c00e137r2p11\) | |
Huawei Tony-al00b | ||
All of | ||
Huawei Tony-tl00b Firmware | <10.0.0.196\(c01e65r2p11\) | |
Huawei Tony-tl00b | ||
All of | ||
Huawei Yale-al00a Firmware | <10.0.0.196\(c00e62r8p12\) | |
Huawei Yale-al00a | ||
All of | ||
Huawei Yale-l21a Firmware | <10.0.0.202\(c10e3r3p2\) | |
Huawei Yale-l21a | ||
All of | ||
Huawei Yalep-al10b Firmware | <10.0.0.194\(c00e62r8p12\) | |
Huawei Yalep-al10b | ||
All of | ||
Huawei Columbia-l29d Firmware | <10.0.0.177\(c432e3r1p4\) | |
Huawei Columbia-l29d | ||
All of | ||
Huawei Honor 20 Pro Firmware | <10.0.0.202\(c10e3r3p2\) | |
Huawei HONOR 20 PRO | ||
All of | ||
Huawei Y6 2019 Firmware | <9.1.0.290\(c431e1r1p8\) | |
Huawei Y6 2019 | ||
All of | ||
Huawei Y6 2019 Firmware | <9.1.0.290\(c605e6r1p6\) | |
Huawei Y6 2019 | ||
All of | ||
Huawei Y6 2019 Firmware | <9.1.0.295\(c431e5r2p2\) | |
Huawei Y6 2019 | ||
All of | ||
Huawei Honor 8a Firmware | <9.1.0.291\(c432e5r2p1\) | |
Huawei Honor 8a | ||
All of | ||
Huawei Honor 8a Firmware | <9.1.0.291\(c636e4r4p1\) | |
Huawei Honor 8a | ||
All of | ||
Huawei Honor 8a Firmware | <9.1.0.297\(c605e4r4p2\) | |
Huawei Honor 8a | ||
All of | ||
Huawei Honor View 20 Firmware | <10.0.0.200\(c185e3r3p3\) | |
Huawei Honor View 20 | ||
All of | ||
Huawei Honor View 20 Firmware | <10.0.0.201\(c10e5r4p3\) | |
Huawei Honor View 20 | ||
Google Android | ||
MediaTek Multiple Chipsets | ||
All of | ||
<10.0.0.177\(c10e3r1p4\) | ||
All of | ||
<10.0.0.178\(c00e178r1p4\) | ||
All of | ||
<10.0.0.177\(c10e4r1p4\) | ||
All of | ||
<10.0.0.178\(c01e178r1p4\) | ||
All of | ||
<10.0.0.178\(c01e178r1p4\) | ||
All of | ||
<9.1.0.340\(c00e333r1p1t8\) | ||
All of | ||
<9.1.0.340\(c01e333r1p1t8\) | ||
All of | ||
<1.0.0.190\(c00\) | ||
All of | ||
<10.0.0.194\(c636e3r3p1\) | ||
All of | ||
<9.1.0.290\(c185e5r4p1\) | ||
All of | ||
<9.1.0.338\(c00e333r1p1t8\) | ||
All of | ||
<10.0.0.160\(c01e32r2p4\) | ||
All of | ||
<9.1.0.291\(c185e3r4p1\) | ||
All of | ||
<10.0.0.198\(c432e10r3p4\) | ||
All of | ||
<9.1.0.251\(c00e106r2p2\) | ||
All of | ||
<9.1.0.146\(c00e131r2p2\) | ||
All of | ||
<9.1.0.160\(c00e150r1p7\) | ||
All of | ||
<9.1.0.261\(c00e120r4p1\) | ||
All of | ||
<9.1.0.380\(c636e1r1p3t8\) | ||
All of | ||
<10.0.0.194\(c00e61r4p11\) | ||
All of | ||
<9.1.0.237\(c00e80r1p7t8\) | ||
All of | ||
<9.1.0.237\(c01e80r1p7t8\) | ||
All of | ||
<10.0.0.159\(c00e64r1p5\) | ||
All of | ||
<10.1.0.137\(c00e137r2p11\) | ||
All of | ||
<10.0.0.196\(c01e65r2p11\) | ||
All of | ||
<10.0.0.196\(c00e62r8p12\) | ||
All of | ||
<10.0.0.202\(c10e3r3p2\) | ||
All of | ||
<10.0.0.194\(c00e62r8p12\) | ||
All of | ||
<10.0.0.177\(c432e3r1p4\) | ||
All of | ||
<10.0.0.202\(c10e3r3p2\) | ||
All of | ||
<9.1.0.290\(c431e1r1p8\) | ||
All of | ||
<9.1.0.290\(c605e6r1p6\) | ||
All of | ||
<9.1.0.295\(c431e5r2p2\) | ||
All of | ||
<9.1.0.291\(c432e5r2p1\) | ||
All of | ||
<9.1.0.291\(c636e4r4p1\) | ||
All of | ||
<9.1.0.297\(c605e4r4p2\) | ||
All of | ||
<10.0.0.200\(c185e3r3p3\) | ||
All of | ||
<10.0.0.201\(c10e5r4p3\) | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.