In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, existing checks in place on partition size are incomplete and can lead to heap overwrite vulnerabilities while loading a secure application from the boot loader.
References
Link | Resource |
---|---|
https://source.codeaurora.org/quic/la/kernel/lk/commit/?id=114a392e29bc900c0fe15cc1f3e9ba369cd03244 | Patch Third Party Advisory |
https://www.codeaurora.org/security-bulletin/2018/11/05/november-2018-code-aurora-forum-security-bulletin | Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: qualcomm
Published: 2018-11-27T18:00:00
Updated: 2018-11-27T17:57:02
Reserved: 2018-01-19T00:00:00
Link: CVE-2018-5861
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-11-27T16:29:01.443
Modified: 2018-12-21T17:22:31.760
Link: CVE-2018-5861
JSON object: View
Redhat Information
No data.
CWE