High severity7.8NVD Advisory· Published Dec 7, 2018· Updated Jun 17, 2026
CVE-2018-9518
CVE-2018-9518
Description
In nfc_llcp_build_sdreq_tlv of llcp_commands.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-73083945.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
- Range: Android kernel
Patches
Vulnerability mechanics
References
3- usn.ubuntu.com/3798-1/nvdPatchThird Party Advisory
- source.android.com/security/bulletin/pixel/2018-09-01nvdVendor Advisory
- usn.ubuntu.com/3798-2/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.