HIGH · 7.5

CVE-2018-19939

The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfr...

Vulnerability Description

The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in drivers/input/touchscreen/gt917d/gt9xx.c.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
MiMi A2 Lite Firmware<= 2018-08-27
MiMi A2 Lite-
MiRedmi 6 Firmware<= 2018-08-27
MiRedmi 6-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-19939?

CVE-2018-19939 is a vulnerability with a CVSS score of 7.5 (HIGH). The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfr...

How severe is CVE-2018-19939?

CVE-2018-19939 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-19939?

Check the references section above for vendor advisories and patch information. Affected products include: Mi Mi A2 Lite Firmware, Mi Mi A2 Lite, Mi Redmi 6 Firmware, Mi Redmi 6.