← Vulnerability feed

Vulnerability record · CVE-2018-19939 · published 7 December 2018

CVE-2018-19939: Mi a2 lite firmware null pointer dereference vulnerability

MMi · Mi A2 Lite Firmware

The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in drivers/input/touchscreen/gt917d/gt9xx.c.

7.5 CVSS 3.1 High EPSS 1.3% · top 31.2% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score, v2 5.0
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

The Goodix GT9xx touchscreen driver for custom Linux kernels on Xiaomi daisy-o-oss and daisy-p-oss as used in Mi A2 Lite and RedMi6 pro devices through 2018-08-27 has a NULL pointer dereference in kfree after a kmalloc failure in gtp_read_Color in drivers/input/touchscreen/gt917d/gt9xx.c.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/MiCode/Xiaomi_Kernel_OpenSource/issues/972 Issue TrackingThird Party Advisory
https://github.com/MiCode/Xiaomi_Kernel_OpenSource/issues/972 Issue TrackingThird Party Advisory

Track CVE-2018-19939 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2018-19939), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.