CVE-2018-3586

CRITICAL

Android - Integer Overflow to Buffer Overflow in ADSPRPC Heap Manager

Title source: llm
STIX 2.1

Description

An integer overflow to buffer overflow vulnerability exists in the ADSPRPC heap manager in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0060
EPSS Percentile 44.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (1)
google/android
Published Jul 06, 2018
Tracked Since Feb 18, 2026