Beveiligingsadvies

CVE-2018-9372

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-11-19 19:23:55
Laatst bijgewerkt 2024-11-21 15:13:16
Toegewezen door google_android
CVSS-score 7.8
Status PUBLISHED

Beschrijving

In cmd_flash_mmc_sparse_img of dl_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to a local escalation of privilege in the bootloader with no additional execution privileges needed. User interaction is not needed for exploitation.