CVE-2018-11894

HIGH

Android - Integer Overflow to Buffer Overflow in Preferred Network Offload Scan Results

Title source: llm
STIX 2.1

Description

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing preferred network offload scan results integer overflow may lead to buffer overflow when large frame length is received from FW.

References (3)

Core 3

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 12.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (1)
google/android
Published Sep 19, 2018
Tracked Since Feb 18, 2026