CVE-2018-9547
Last modified
CVE-2018-9547 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In unflatten of GraphicBuffer.cpp, there is a possible bad fd close due to improper input validation. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.1 Android-9. Android ID: A-114223584.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | 8.1 | |
| Android | 9.0 |
References
- http://www.securityfocus.com/bid/106067Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-12-01Patch, Vendor Advisory
- http://www.securityfocus.com/bid/106067Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-12-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-9547?
How severe is CVE-2018-9547?
How do I fix CVE-2018-9547?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-9540In avrc_ctrl_pars_vendor_rsp of avrc_pars_ct.c, there is a p…
- CVE-2018-9541In avrc_pars_vendor_rsp of avcr_pars_ct.cc, there is a possi…
- CVE-2018-9542In avrc_pars_vendor_rsp of avrc_pars_ct.cc, there is a possi…
- CVE-2018-9543In trim_device of f2fs_format_utils.c, it is possible that t…
- CVE-2018-9544In register_app of btif_hd.cc, there is a possible out-of-bo…
- CVE-2018-9545In BTA_HdRegisterApp of bta_hd_api.cc, there is a possible o…
- CVE-2018-9548In multiple functions of ContentProvider.java, there is a po…5.5
- CVE-2018-9549In lppTransposer of lpp_tran.cpp there is a possible out of …7.8
- CVE-2018-9550In CAacDecoder_Init of aacdecoder.cpp, there is a possible o…7.8
- CVE-2018-9551In CAacDecoder_Init of aacdecoder.cpp, there is a possible o…7.8
- CVE-2018-9552In ihevcd_sao_shift_ctb of ihevcd_sao.c there is a possible …5.5
- CVE-2018-9553In MasteringMetadata::Parse of mkvparser.cc there is a possi…7.8
Are you affected by CVE-2018-9547?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
