In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, double free of memory allocation is possible in Kernel when it explicitly tries to free that memory on driver probe failure, since memory allocated is automatically freed on probe.
References
Link | Resource |
---|---|
https://www.codeaurora.org/security-bulletin/2018/09/04/september-2018-code-aurora-security-bulletin | Patch Third Party Advisory |
https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=83a44ca6057bf9c1e36515cded28edc32a4a1501 | Patch Third Party Advisory |
https://source.android.com/security/bulletin/pixel/2018-09-01#qualcomm-components | Patch Vendor Advisory |
Configurations
Information
Published : 2018-09-18 11:29
Updated : 2018-11-09 10:24
NVD link : CVE-2018-11276
Mitre link : CVE-2018-11276
JSON object : View
CWE
CWE-415
Double Free
Products Affected
- android