CVE-2018-9419
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 19, 2024
Updated: Nov 22, 2024
CWE ID 125
CWE ID 787
Summary
CVE-2018-9419 is a vulnerability affecting the l2c_ble.cc file in the Linux Bluetooth subsystem. The issue lies in the function 'l2cble_process_sig_cmd' where a bounds check is missing, leading to a possible out-of-bounds read. This flaw can result in remote information disclosure, allowing attackers to access sensitive data without requiring any additional execution privileges. User interaction is not necessary for exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Android