CVE-2018-11987

HIGH

Android - Use-After-Free in Secure Memory Pool Allocation

Title source: llm
STIX 2.1

Description

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, if there is an unlikely memory alloc failure for the secure pool in boot, it can result in wrong pointer access causing kernel panic.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0017
EPSS Percentile 6.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-415
Status published
Products (1)
google/android
Published Dec 20, 2018
Tracked Since Feb 18, 2026