In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of check on buffer length while processing debug log event from firmware can lead to an integer overflow.
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/pixel/2018-09-01#qualcomm-components | Patch Vendor Advisory |
https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=31ad3a5a7458e60f5e0ba4f492cebe1f1bda0964 | Patch Third Party Advisory |
https://www.codeaurora.org/security-bulletin/2018/09/04/september-2018-code-aurora-security-bulletin | Patch Third Party Advisory |
https://source.android.com/security/bulletin/pixel/2018-09-01#qualcomm-components | Patch Vendor Advisory |
https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=31ad3a5a7458e60f5e0ba4f492cebe1f1bda0964 | Patch Third Party Advisory |
https://www.codeaurora.org/security-bulletin/2018/09/04/september-2018-code-aurora-security-bulletin | Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-09-18 18:29
Updated : 2024-11-21 03:43
NVD link : CVE-2018-11301
Mitre link : CVE-2018-11301
CVE.ORG link : CVE-2018-11301
JSON object : View
Products Affected
- android
CWE
CWE-191
Integer Underflow (Wrap or Wraparound)