CVE-2018-5859
Summary
| CVE | CVE-2018-5859 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-06 19:29:00 UTC |
| Updated | 2018-08-27 17:20:00 UTC |
| Description | Due to a race condition in the MDSS MDP driver in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, a Use After Free condition can occur. |
Risk And Classification
Problem Types: CWE-362 | CWE-416
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| kernel/msm-3.18 - Unnamed repository; edit this file 'description' to name the repository. | CONFIRM | source.codeaurora.org | Patch |
| July 2018 Code Aurora Security Bulletin - Code Aurora | CONFIRM | www.codeaurora.org | Patch |
| Pixel / Nexus Security Bulletin—July 2018 | CONFIRM | source.android.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.