CVE-2018-9543 PUBLISHED

In trim_device of f2fs_format_utils.c, it is possible that the data partition is not wiped during a factory reset. This could lead to local information disclosure after factory reset with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-112868088.

EPSS 0.04% · 11.3th percentile

Risk Scores

EPSS Score
0.04%
11.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSf2fs-tools1.6.0-1, 1.6.1-1, 1.6.0-2
Ubuntu:18.04:LTSf2fs-tools1.10.0-1, 1.11.0-1.1~18.04, 0
Ubuntu:22.04:LTSf2fs-tools1.14.0-2build1, 0
Ubuntu:25.10f2fs-tools1.16.0-1.1, 1.16.0-2, 0
Ubuntu:24.04:LTSf2fs-tools1.16.0-1, 0
Ubuntu:20.04:LTSf2fs-tools1.11.0-1.1, 0, 1.11.0-1.1ubuntu1

Timeline

References

Open in Interactive Console →