CVE-2018-14745

Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to overwrite kernel memory due to improper validation of the ring buffer read pointer. The Samsung ID is SVE-2018-12029.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:galaxy_s6_firmware:g920fxxu5eqh7:*:*:*:*:*:*:*
cpe:2.3:h:samsung:galaxy_s6:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:49

Type Values Removed Values Added
References () https://github.com/securesystemslab/periscope/blob/master/bugs-found/CVE-2018-14745.md - Exploit, Third Party Advisory () https://github.com/securesystemslab/periscope/blob/master/bugs-found/CVE-2018-14745.md - Exploit, Third Party Advisory
References () https://pastebin.com/tmFrECnZ - Exploit, Third Party Advisory () https://pastebin.com/tmFrECnZ - Exploit, Third Party Advisory
References () https://security.samsungmobile.com/securityUpdate.smsb - Vendor Advisory () https://security.samsungmobile.com/securityUpdate.smsb - Vendor Advisory

Information

Published : 2019-03-21 16:00

Updated : 2024-11-21 03:49


NVD link : CVE-2018-14745

Mitre link : CVE-2018-14745

CVE.ORG link : CVE-2018-14745


JSON object : View

Products Affected

samsung

  • galaxy_s6
  • galaxy_s6_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer