CVE-2018-11270

HIGH

Android - Use-After-Free in devm_kzalloc Memory Handling

Title source: llm
STIX 2.1

Description

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, memory allocated with devm_kzalloc is automatically released by the kernel if the probe function fails with an error code. This may result in data corruption.

Scores

CVSS v3 7.8
EPSS 0.0019
EPSS Percentile 9.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-415
Status published
Products (1)
google/android
Published Sep 18, 2018
Tracked Since Feb 18, 2026