CVE-2018-5861
Last modified
CVE-2018-5861 is a vulnerability of currently unknown severity. In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, existing checks in place on partition size are incomplete and can lead to heap overwrite vulnerabilities while loading a secure application from the boot loader.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, existing checks in place on partition size are incomplete and can lead to heap overwrite vulnerabilities while loading a secure application from the boot loader.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
- https://source.codeaurora.org/quic/la/kernel/lk/commit/?id=114a392e29bc900c0fe15cc1f3e9ba369cd03244Patch, Third Party Advisory
- https://www.codeaurora.org/security-bulletin/2018/11/05/november-2018-code-aurora-forum-security-bulletinPatch, Third Party Advisory
- https://source.codeaurora.org/quic/la/kernel/lk/commit/?id=114a392e29bc900c0fe15cc1f3e9ba369cd03244Patch, Third Party Advisory
- https://www.codeaurora.org/security-bulletin/2018/11/05/november-2018-code-aurora-forum-security-bulletinPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5861?
How severe is CVE-2018-5861?
How do I fix CVE-2018-5861?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5855While padding or shrinking a nested wmi packet in all Androi…
- CVE-2018-5856In all android releases(Android for MSM, Firefox OS for MSM,…
- CVE-2018-5857In the WCD CPE codec, a Use After Free condition can occur i…
- CVE-2018-5858In the audio debugfs in all Android releases from CAF using …
- CVE-2018-5859Due to a race condition in the MDSS MDP driver in all Androi…
- CVE-2018-5860In the MDSS driver in all Android releases(Android for MSM, …
- CVE-2018-5862In __wlan_hdd_cfg80211_vendor_scan() in all Android releases…
- CVE-2018-5863If userspace provides a too-large WPA RSN IE length in wlan_…
- CVE-2018-5864While processing a WMI_APFIND event in all Android releases …
- CVE-2018-5865While processing a debug log event from firmware in all Andr…
- CVE-2018-5866While processing logs, data is copied into a buffer pointed …
- CVE-2018-5867Lack of checking input size can lead to buffer overflow In W…
Are you affected by CVE-2018-5861?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
