CVE-2018-5849 Information
Feb 14, 2021
cve
Description
Due to a race condition in the QTEECOM driver in all Android releases from CAF (Android for MSM Firefox OS for MSM QRD Android) using the Linux Kernel when more than one HLOS client loads the same TA a Use After Free condition can occur.
CVSS Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://source.android.com/security/bulletin/pixel/2018-05-01 https://www.codeaurora.org/security-bulletin/2018/05/11/may-2018-code-aurora-security-bulletin-2
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.0
Share on: