Vulnerability Description
drivers/leds/leds-aw2023.c in the led driver for custom Linux kernels on the Xiaomi Redmi 6pro daisy-o-oss phone has several integer overflows because of a left-shifting operation when the right-hand operand can be equal to or greater than the integer length. This can be exploited by a crafted application for denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Micode | Xiaomi Perseus-P-Oss | <= 2018-11-26 |
Related Weaknesses (CWE)
References
- https://github.com/MiCode/Xiaomi_Kernel_OpenSource/issues/973Third Party Advisory
- https://github.com/MiCode/Xiaomi_Kernel_OpenSource/issues/973Third Party Advisory
FAQ
What is CVE-2018-20788?
CVE-2018-20788 is a vulnerability with a CVSS score of 5.5 (MEDIUM). drivers/leds/leds-aw2023.c in the led driver for custom Linux kernels on the Xiaomi Redmi 6pro daisy-o-oss phone has several integer overflows because of a left-shifting operation when the right-hand ...
How severe is CVE-2018-20788?
CVE-2018-20788 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20788?
Check the references section above for vendor advisories and patch information. Affected products include: Micode Xiaomi Perseus-P-Oss.