CVE-2018-11300
HIGHAndroid - Use-After-Free in WLAN Function via Callback Execution
Title source: llmDescription
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, callback executed from the other thread has freed memory which is also used in wlan function and may result in to a "Use after free" scenario.
References (3)
Core 3
Core References
Patch, Third Party Advisory x_refsource_confirm
https://www.codeaurora.org/security-bulletin/2018/09/04/september-2018-code-aurora-security-bulletin
Patch, Third Party Advisory x_refsource_confirm
https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=1f111832dc93bc639538dc173397b30af329b130
Patch, Vendor Advisory x_refsource_confirm
https://source.android.com/security/bulletin/pixel/2018-09-01#qualcomm-components
Scores
CVSS v3
7.8
EPSS
0.0018
EPSS Percentile
7.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-416
Status
published
Products (1)
google/android
Published
Sep 18, 2018
Tracked Since
Feb 18, 2026