CVE-2018-5859
UnknownEPSS 0.13%
Last modified
CVE-2018-5859 is a vulnerability of currently unknown severity. Due to a race condition in the MDSS MDP driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, a Use After Free condition can occur.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
Due to a race condition in the MDSS MDP driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, a Use After Free condition can occur.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
- https://source.android.com/security/bulletin/pixel/2018-07-01Patch, Vendor Advisory
- https://source.android.com/security/bulletin/pixel/2018-07-01Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5859?
Due to a race condition in the MDSS MDP driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, a Use After Free condition can occur.
How severe is CVE-2018-5859?
Severity scoring for CVE-2018-5859 is pending analysis. The EPSS model estimates a 0.13% probability of exploitation in the next 30 days.
How do I fix CVE-2018-5859?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5853A race condition exists in a driver in all Android releases …
- CVE-2018-5854A stack-based buffer overflow can occur in fastboot from all…
- CVE-2018-5855While padding or shrinking a nested wmi packet in all Androi…
- CVE-2018-5856In all android releases(Android for MSM, Firefox OS for MSM,…
- CVE-2018-5857In the WCD CPE codec, a Use After Free condition can occur i…
- CVE-2018-5858In the audio debugfs in all Android releases from CAF using …
- CVE-2018-5860In the MDSS driver in all Android releases(Android for MSM, …
- CVE-2018-5861In all android releases(Android for MSM, Firefox OS for MSM,…
- CVE-2018-5862In __wlan_hdd_cfg80211_vendor_scan() in all Android releases…
- CVE-2018-5863If userspace provides a too-large WPA RSN IE length in wlan_…
- CVE-2018-5864While processing a WMI_APFIND event in all Android releases …
- CVE-2018-5865While processing a debug log event from firmware in all Andr…
Are you affected by CVE-2018-5859?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
