Vulnerabilities > CVE-2018-19939 - NULL Pointer Dereference vulnerability in MI A2 Lite Firmware and Redmi 6 Firmware

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
mi
CWE-476

Summary

The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in drivers/input/touchscreen/gt917d/gt9xx.c.

Vulnerable Configurations

Part Description Count
OS
Mi
2
Hardware
Mi
2

Common Weakness Enumeration (CWE)