Due to a race condition in the QTEECOM driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, when more than one HLOS client loads the same TA, a Use After Free condition can occur.
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/pixel/2018-05-01 | Third Party Advisory |
https://www.codeaurora.org/security-bulletin/2018/05/11/may-2018-code-aurora-security-bulletin-2 | Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-06-12 20:29
Updated : 2018-08-03 18:37
NVD link : CVE-2018-5849
Mitre link : CVE-2018-5849
CVE.ORG link : CVE-2018-5849
JSON object : View
Products Affected
- android