CVE-2018-20788

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
25/02/2019
Last modified:
26/02/2019

Description

drivers/leds/leds-aw2023.c in the led driver for custom Linux kernels on the Xiaomi Redmi 6pro daisy-o-oss phone has several integer overflows because of a left-shifting operation when the right-hand operand can be equal to or greater than the integer length. This can be exploited by a crafted application for denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:micode:xiaomi_perseus-p-oss:*:*:*:*:*:*:*:* 2018-11-26 (including)


References to Advisories, Solutions, and Tools