CVE-2018-5849

HIGH

Android QTEECOM Driver - Use-After-Free via Race Condition in TA Loading

Title source: llm
STIX 2.1

Description

Due to a race condition in the QTEECOM driver in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel, when more than one HLOS client loads the same TA, a Use After Free condition can occur.

References (2)

Core 2

Scores

CVSS v3 7.0
EPSS 0.0012
EPSS Percentile 2.0%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362 CWE-416
Status published
Products (1)
google/android
Published Jun 12, 2018
Tracked Since Feb 18, 2026