Vulnerability Description
An integer overflow to buffer overflow vulnerability exists in the ADSPRPC heap manager in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | - |
Related Weaknesses (CWE)
References
- https://source.android.com/security/bulletin/2018-07-01#qualcomm-componentsVendor Advisory
- https://source.android.com/security/bulletin/2018-07-01#qualcomm-componentsVendor Advisory
FAQ
What is CVE-2018-3586?
CVE-2018-3586 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An integer overflow to buffer overflow vulnerability exists in the ADSPRPC heap manager in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
How severe is CVE-2018-3586?
CVE-2018-3586 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-3586?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android.