NULL pointer dereference in Google Android - CVE-2018-12014

 

NULL pointer dereference in Google Android - CVE-2018-12014

Published: February 11, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36157
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-12014
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Google
Affected software:
Google Android

Detailed vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Null pointer dereference vulnerability may occur due to missing NULL assignment in NAT module of freed pointer. A remote attacker can perform a denial of service (DoS) attack.


How to mitigate CVE-2018-12014

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Sources