{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2018-9376","assignerOrgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","state":"PUBLISHED","assignerShortName":"google_android","dateReserved":"2018-04-05T00:00:00.000Z","datePublished":"2024-12-02T20:59:25.345Z","dateUpdated":"2024-12-03T18:39:18.952Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Android","vendor":"Google","versions":[{"status":"affected","version":"6"},{"status":"affected","version":"6.0.1"},{"status":"affected","version":"7"},{"status":"affected","version":"7.1.1"},{"status":"affected","version":"7.1.2"},{"status":"affected","version":"8"},{"status":"affected","version":"8.1"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span style=\"background-color: rgb(255, 255, 255);\">In rpc_msg_handler and related handlers of&nbsp;</span><span style=\"background-color: rgb(255, 255, 255);\">drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds&nbsp;</span><span style=\"background-color: rgb(255, 255, 255);\">write due to an incorrect bounds check. This could lead to local escalation&nbsp;</span><span style=\"background-color: rgb(255, 255, 255);\">of privilege with System execution privileges needed. User interaction is&nbsp;</span><span style=\"background-color: rgb(255, 255, 255);\">not needed for exploitation.</span><br>"}],"value":"In rpc_msg_handler and related handlers of drivers/misc/mediatek/eccci/port_rpc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation."}],"providerMetadata":{"orgId":"baff130e-b8d5-4e15-b3d3-c3cf5d5545c6","shortName":"google_android","dateUpdated":"2024-12-02T20:59:25.345Z"},"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2018-07-01"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-787","lang":"en","description":"CWE-787 Out-of-bounds Write"}]}],"affected":[{"vendor":"google","product":"android","cpes":["cpe:2.3:o:google:android:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"2018-07-05","versionType":"custom"}]},{"vendor":"google","product":"pixel","cpes":["cpe:2.3:h:google:pixel:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"2018-07-05","versionType":"custom"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.8,"attackVector":"LOCAL","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-12-03T18:38:15.430097Z","id":"CVE-2018-9376","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-12-03T18:39:18.952Z"}}]}}