UBUNTU-CVE-2018-9517
In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38159931.
02 / AFFECTED SOFTWARE
Affected packages
26 explicit affected versions
66 explicit affected versions
88 explicit affected versions
47 explicit affected versions
15 explicit affected versions
15 explicit affected versions
34 explicit affected versions
26 explicit affected versions
60 explicit affected versions
58 explicit affected versions
4 explicit affected versions
26 explicit affected versions
51 explicit affected versions
6 explicit affected versions
12 explicit affected versions
1 explicit affected versions
1 explicit affected versions
23 explicit affected versions
7 explicit affected versions
7 explicit affected versions
8 explicit affected versions
7 explicit affected versions
1 explicit affected versions
191 explicit affected versions
3 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
In pppol2tp_connect, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-38159931.
05 / REFERENCES
Further evidence
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f026bc29a8e093edfbb2a77700454b285c97e8ad
- https://source.android.com/security/bulletin/pixel/2018-09-01
- https://ubuntu.com/security/CVE-2018-9517
- https://ubuntu.com/security/notices/USN-3932-1
- https://ubuntu.com/security/notices/USN-3932-2
- https://www.cve.org/CVERecord?id=CVE-2018-9517