CVE Vulnerabilities

CVE-2018-9421

Use of Uninitialized Resource

Published: Nov 19, 2024 | Modified: Nov 22, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In writeInplace of Parcel.cpp, there is a possible information leak across processes, using Binder, due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
AndroidGoogle6.0 (including)6.0 (including)
AndroidGoogle6.0.1 (including)6.0.1 (including)
AndroidGoogle7.0 (including)7.0 (including)
AndroidGoogle7.1.1 (including)7.1.1 (including)
AndroidGoogle7.1.2 (including)7.1.2 (including)
AndroidGoogle8.0 (including)8.0 (including)
AndroidGoogle8.1 (including)8.1 (including)

Potential Mitigations

References