CVE-2018-9518 PUBLISHED

In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-73083945.

EPSS 0.07% · 21.0th percentile

Risk Scores

EPSS Score
0.07%
21.0th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux4.15.0-24.26, 4.15.0-23.25, 4.15.0-22.24
Ubuntu:16.04:LTSlinux-azure4.13.0-1014.17, 4.13.0-1012.15, 4.13.0-1011.14
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1005.5, 4.4.0-1006.6, 4.4.0-1003.3
Ubuntu:18.04:LTSlinux-gcp4.15.0-1001.1, 0, 4.15.0-1018.19
Ubuntu:18.04:LTSlinux-aws4.15.0-1011.11, 4.15.0-1005.5, 4.15.0-1003.3
Ubuntu:20.04:LTSlinux-raspi20, 5.3.0-1007.8, 5.4.0-1006.6
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1026.29, 4.4.0-1030.33, 4.4.0-1032.36
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-96.119~14.04.1, 0, 4.4.0-13.29~14.04.1
Ubuntu:18.04:LTSlinux-oem0, 4.15.0-1017.20, 4.15.0-1015.18
Ubuntu:16.04:LTSlinux-hwe4.10.0-42.46~16.04.1, 4.8.0-39.42~16.04.1, 4.8.0-41.44~16.04.1
Ubuntu:22.04:LTSlinux-riscv0, 5.13.0-1004.4, 5.13.0-1006.6+22.04.1
Ubuntu:20.04:LTSlinux-riscv5.4.0-24.28, 5.4.0-40.45, 5.4.0-39.44
Ubuntu:16.04:LTSlinux-gcp4.13.0-1012.16, 4.10.0-1007.7, 4.10.0-1006.6
Ubuntu:18.04:LTSlinux-kvm0, 4.15.0-1020.20, 4.15.0-1019.19
Ubuntu:16.04:LTSlinux-aws4.4.0-1039.48, 4.4.0-1041.50, 4.4.0-1043.52
Ubuntu:18.04:LTSlinux-raspi24.15.0-1020.22, 4.15.0-1021.23, 4.15.0-1013.14
Ubuntu:20.04:LTSlinux-gke5.4.0-1055.58, 5.4.0-1057.60, 5.4.0-1059.62
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35
Ubuntu:14.04:LTSlinux3.13.0-143.192, 0, 3.11.0-12.19

…and 7 more

Timeline

References

Open in Interactive Console →