CVE-2019-8413: Mi Mix 2 Firmware

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

On Xiaomi MIX 2 devices with the 4.4.78 kernel, a NULL pointer dereference in the ioctl interface of the device file /dev/elliptic1 or /dev/elliptic0 causes a system crash via IOCTL 0x4008c575 (aka decimal 1074316661).

Affected products

  • Mi Mi Mix 2 Firmware: version 4.4.78 only

Published 2019-02-17. Last modified 2026-06-17.