Out-of-bounds read in Google Android - CVE-2018-11278

 

Out-of-bounds read in Google Android - CVE-2018-11278

Published: September 18, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36656
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-11278
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Google
Affected software:
Google Android

Detailed vulnerability description

The vulnerability allows a local authenticated user to #BASIC_IMPACT#.

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Venus HW searches for start code when decoding input bit stream buffers. If start code is not found in entire buffer, there is over-fetch beyond allocation length. This leads to page fault.


How to mitigate CVE-2018-11278

Install update from vendor's website.

Sources