CVE-2018-11270
HIGHGoogle Android - Double Free
Title source: ruleDescription
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, memory allocated with devm_kzalloc is automatically released by the kernel if the probe function fails with an error code. This may result in data corruption.
Scores
CVSS v3
7.8
EPSS
0.0006
EPSS Percentile
19.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-415
Status
published
Affected Products (1)
google/android
Timeline
Published
Sep 18, 2018
Tracked Since
Feb 18, 2026