SB2018091923 - Input validation error in Google, Google Android



SB2018091923 - Input validation error in Google, Google Android

Published: September 19, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018091923
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2018-3574)

The vulnerability allows a local authenticated user to manipulate data.

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, userspace can request ION cache maintenance on a secure ION buffer for which the ION_FLAG_SECURE ion flag is not set and cause the kernel to attempt to perform cache maintenance on memory which does not belong to HLOS.


Remediation

Install update from vendor's website.