CVE-2018-11262

HIGH

Android - Out-of-Bounds Write via GPT Partition Count Calculation

Title source: llm
STIX 2.1

Description

In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while trying to find out total number of partition via a non zero check, there could be possibility where the 'TotalPart' could cross 'GptHeader->MaxPtCnt' and which could result in OOB write in patching GPT.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106949

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 10.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-682 CWE-787
Status published
Products (1)
google/android
Published Sep 04, 2018
Tracked Since Feb 18, 2026