CVE-2018-11278 Information
Feb 14, 2021
cve
Description
In all android releases (Android for MSM Firefox OS for MSM QRD Android) from CAF using the linux kernel Venus HW searches for start code when decoding input bit stream buffers. If start code is not found in entire buffer there is over-fetch beyond allocation length. This leads to page fault.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Reference
https://source.codeaurora.org/quic/la/platform/hardware/qcom/media/commit/?id=6c7dbdb2f067bf844beef2c41d9d67cacc3adfa6 https://www.codeaurora.org/security-bulletin/2018/09/04/september-2018-code-aurora-security-bulletin
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.1
Share on: