CVE-2018-19939

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
07/12/2018
Last modified:
09/12/2022

Description

The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in drivers/input/touchscreen/gt917d/gt9xx.c.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mi:mi_a2_lite_firmware:*:*:*:*:*:*:*:* 2018-08-27 (including)
cpe:2.3:h:mi:mi_a2_lite:-:*:*:*:*:*:*:*
cpe:2.3:o:mi:redmi_6_firmware:*:*:*:*:*:*:*:* 2018-08-27 (including)
cpe:2.3:h:mi:redmi_6:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools