Vulnerability Description
The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in drivers/input/touchscreen/gt917d/gt9xx.c.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mi | Mi A2 Lite Firmware | <= 2018-08-27 |
| Mi | Mi A2 Lite | - |
| Mi | Redmi 6 Firmware | <= 2018-08-27 |
| Mi | Redmi 6 | - |
Related Weaknesses (CWE)
References
- https://github.com/MiCode/Xiaomi_Kernel_OpenSource/issues/972Issue TrackingThird Party Advisory
- https://github.com/MiCode/Xiaomi_Kernel_OpenSource/issues/972Issue TrackingThird Party Advisory
FAQ
What is CVE-2018-19939?
CVE-2018-19939 is a vulnerability with a CVSS score of 7.5 (HIGH). The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfr...
How severe is CVE-2018-19939?
CVE-2018-19939 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19939?
Check the references section above for vendor advisories and patch information. Affected products include: Mi Mi A2 Lite Firmware, Mi Mi A2 Lite, Mi Redmi 6 Firmware, Mi Redmi 6.