CVE-2018-9417

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 19, 2024
Updated: Nov 21, 2024
CWE ID 416

Summary

CVE-2018-9417 is a vulnerability affecting the Linux kernel's Human Interface Device (HID) subsystem. Specifically, in the functions f_hidg_read and hidg_disable of f_hid.c, there is a potential use-after-free issue caused by inadequate locking. This defect allows a local attacker to escalate privileges without requiring any additional execution privileges. Notably, user interaction is not necessary for an exploit to succeed.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share