CVE-2018-20787

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
25/02/2019
Last modified:
26/02/2019

Description

The ft5x46 touchscreen driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the size argument in tpdbg_write in drivers/input/touchscreen/ft5x46/ft5x46_ts.c. This is exploitable for a device crash via a syscall by a crafted application on a rooted device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:micode:xiaomi_perseus-p-oss:*:*:*:*:*:*:*:* 2018-11-26 (including)


References to Advisories, Solutions, and Tools