Input validation error in Google Android - CVE-2018-6241

 

Input validation error in Google Android - CVE-2018-6241

Published: January 31, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36178
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6241
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

NVIDIA Tegra Gralloc module contains a vulnerability in driver in which it does not validate input parameter of the registerbuffer API, which may lead to arbitrary code execution, denial of service, or escalation of privileges. Android ID: A-62540032 Severity Rating: High Version: N/A.


Affected software

Google Android

How to mitigate CVE-2018-6241

Install update from vendor's website.


External References

Related Security Bulletins