Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to overwrite kernel memory due to improper validation of the ring buffer read pointer. The Samsung ID is SVE-2018-12029.
2019-03-21T16:00:20.890
2024-11-21T03:49:43.760
Modified
CVSSv3.0: 8.8 (HIGH)
AV:A/AC:L/Au:N/C:P/I:P/A:P
6.5
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | samsung | galaxy_s6_firmware | g920fxxu5eqh7 | Yes |
Hardware | samsung | galaxy_s6 | - | No |