Race condition in Google Android - CVE-2018-11818

 

Race condition in Google Android - CVE-2018-11818

Published: September 18, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36670
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11818
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, LUT configuration is passed down to driver from userspace via ioctl. Simultaneous update from userspace while kernel drivers are updating LUT registers can lead to race condition.


Affected software

Google Android

How to mitigate CVE-2018-11818

Install update from vendor's website.


External References

Related Security Bulletins