CVE-2018-11276

HIGH

Android - Use-After-Free in Kernel Driver Probe

Title source: llm
STIX 2.1

Description

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, double free of memory allocation is possible in Kernel when it explicitly tries to free that memory on driver probe failure, since memory allocated is automatically freed on probe.

Scores

CVSS v3 7.8
EPSS 0.0019
EPSS Percentile 8.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-415
Status published
Products (1)
google/android
Published Sep 18, 2018
Tracked Since Feb 18, 2026