In the ClearKey CAS descrambler, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-113027383
References
Link Resource
http://www.securityfocus.com/bid/105865 Third Party Advisory VDB Entry
https://source.android.com/security/bulletin/2018-11-01 Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: google_android

Published: 2018-11-14T18:00:00

Updated: 2018-11-15T10:57:01

Reserved: 2018-04-05T00:00:00


Link: CVE-2018-9539

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-11-14T18:29:00.963

Modified: 2018-12-17T19:37:36.620


Link: CVE-2018-9539

JSON object: View

cve-icon Redhat Information

No data.

CWE