CVE-2018-20509

The print_binder_ref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading " ref *desc *node" lines in a debugfs file.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:4.14.90:*:*:*:*:*:*:*

History

21 Nov 2024, 04:01

Type Values Removed Values Added
References () https://github.com/Yellow-Pay/CVE/blob/master/CVE-2018-20509.md - Third Party Advisory () https://github.com/Yellow-Pay/CVE/blob/master/CVE-2018-20509.md - Third Party Advisory
References () https://security.netapp.com/advisory/ntap-20190517-0002/ - () https://security.netapp.com/advisory/ntap-20190517-0002/ -
References () https://www.mail-archive.com/debian-security-tracker%40lists.debian.org/msg03902.html - () https://www.mail-archive.com/debian-security-tracker%40lists.debian.org/msg03902.html -

07 Nov 2023, 02:56

Type Values Removed Values Added
References
  • {'url': 'https://www.mail-archive.com/debian-security-tracker@lists.debian.org/msg03902.html', 'name': '[debian-security-tracker] 20190412 CVE-2018-20509', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'MLIST'}
  • () https://www.mail-archive.com/debian-security-tracker%40lists.debian.org/msg03902.html -

Information

Published : 2019-04-30 18:29

Updated : 2024-11-21 04:01


NVD link : CVE-2018-20509

Mitre link : CVE-2018-20509

CVE.ORG link : CVE-2018-20509


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor