CVE-2018-5831
UnknownEPSS 0.19%
Last modified
CVE-2018-5831 is a vulnerability of currently unknown severity. In the KGSL driver in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, a reference counting error can lead to a Use After Free condition.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In the KGSL driver in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, a reference counting error can lead to a Use After Free condition.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
- https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=e3e13d745238ad8853af47c2d938344ea8d3c77fPatch, Third Party Advisory
- https://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-security-bulletinPatch, Third Party Advisory
- https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=e3e13d745238ad8853af47c2d938344ea8d3c77fPatch, Third Party Advisory
- https://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-security-bulletinPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5831?
In the KGSL driver in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, a reference counting error can lead to a Use After Free condition.
How severe is CVE-2018-5831?
Severity scoring for CVE-2018-5831 is pending analysis. The EPSS model estimates a 0.19% probability of exploitation in the next 30 days.
How do I fix CVE-2018-5831?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5825In Qualcomm Android for MSM, Firefox OS for MSM, and QRD And…
- CVE-2018-5826In Qualcomm Android for MSM, Firefox OS for MSM, and QRD And…
- CVE-2018-5827In Qualcomm Android for MSM, Firefox OS for MSM, and QRD And…
- CVE-2018-5828In Qualcomm Android for MSM, Firefox OS for MSM, and QRD And…
- CVE-2018-5829In wlan_hdd_cfg80211_set_privacy_ibss() in Android releases …
- CVE-2018-5830While processing the HTT_T2H_MSG_TYPE_MGMT_TX_COMPL_IND mess…
- CVE-2018-5832Due to a race condition in a camera driver ioctl handler in …
- CVE-2018-5834In __wlan_hdd_cfg80211_vendor_scan(), a buffer overwrite can…
- CVE-2018-5835If the seq_len is greater then CSR_MAX_RSC_LEN, a buffer ove…
- CVE-2018-5836In wma_nan_rsp_event_handler() in Android releases from CAF …
- CVE-2018-5837In Snapdragon (Automobile, Mobile, Wear) in version IPQ8074,…
- CVE-2018-5838Improper Validation of Array Index In the adreno OpenGL driv…
Are you affected by CVE-2018-5831?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
