CVE-2018-19939
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
07/12/2018
Last modified:
09/12/2022
Description
The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in drivers/input/touchscreen/gt917d/gt9xx.c.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mi:mi_a2_lite_firmware:*:*:*:*:*:*:*:* | 2018-08-27 (including) | |
| cpe:2.3:h:mi:mi_a2_lite:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mi:redmi_6_firmware:*:*:*:*:*:*:*:* | 2018-08-27 (including) | |
| cpe:2.3:h:mi:redmi_6:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



