Vulnerability Description
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, buffer overflow occur may occur in display handlers due to lack of checking in buffer size before copying into it and will lead to memory corruption.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Android | - |
Related Weaknesses (CWE)
References
- https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?id=2c1716c5afd66065PatchThird Party Advisory
- https://www.codeaurora.org/security-bulletin/2018/11/05/november-2018-code-aurorPatchThird Party Advisory
- https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?id=2c1716c5afd66065PatchThird Party Advisory
- https://www.codeaurora.org/security-bulletin/2018/11/05/november-2018-code-aurorPatchThird Party Advisory
FAQ
What is CVE-2018-5909?
CVE-2018-5909 is a vulnerability with a CVSS score of 7.8 (HIGH). In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, buffer overflow occur may occur in display handlers due to lack of checking in buffer size be...
How severe is CVE-2018-5909?
CVE-2018-5909 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5909?
Check the references section above for vendor advisories and patch information. Affected products include: Google Android.