CVE-2018-14852

Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause invalid accesses to operating system memory due to improper validation of the network interface index provided by the Wi-Fi chip's firmware.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:samsung:galaxy_s6_firmware:g920fxxu5eqh7:*:*:*:*:*:*:*
cpe:2.3:h:samsung:galaxy_s6:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:49

Type Values Removed Values Added
References () https://github.com/securesystemslab/periscope/blob/master/bugs-found/CVE-2018-14852.md - Exploit, Third Party Advisory () https://github.com/securesystemslab/periscope/blob/master/bugs-found/CVE-2018-14852.md - Exploit, Third Party Advisory

Information

Published : 2018-12-17 19:29

Updated : 2024-11-21 03:49


NVD link : CVE-2018-14852

Mitre link : CVE-2018-14852

CVE.ORG link : CVE-2018-14852


JSON object : View

Products Affected

samsung

  • galaxy_s6
  • galaxy_s6_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer