In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
Subscriptions
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1715-1 | linux-4.9 security update |
Debian DLA |
DLA-1731-1 | linux security update |
Debian DLA |
DLA-1731-2 | linux regression update |
EUVD |
EUVD-2018-17615 | In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: qualcomm
Published:
Updated: 2024-09-17T00:31:46.093Z
Reserved: 2018-01-19T00:00:00.000Z
Link: CVE-2018-5848
No data.
Status : Modified
Published: 2018-06-12T20:29:00.983
Modified: 2024-11-21T04:09:32.397
Link: CVE-2018-5848
OpenCVE Enrichment
No data.
Debian DLA
EUVD