The printbinderref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading " ref *desc *node" lines in a debugfs file.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20509.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "4.14.90" } ] } ]