CVE-2018-21054
Severity CVSS v4.0:
Pending analysis
Type:
CWE-190
Integer Overflow or Wraparound
Publication date:
08/04/2020
Last modified:
11/02/2023
Description
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0) except MSM8939, N(7.1) except MSM8996 SDM6xx/M6737T software. There is an integer underflow with a resultant buffer overflow in eCryptFS. The Samsung ID is SVE-2017-11857 (September 2018).
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:7.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:7.1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:7.1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:7.1.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:8.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:8.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:samsung:exynos_9610:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:samsung:exynos_9820:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:h:qualcomm:msm8909:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:qualcomm:msm9830:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:samsung:exynos_3470:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:samsung:exynos_5420:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:unisoc:sc7715:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



