Out-of-bounds read in Google Android - CVE-2018-5886

 

Out-of-bounds read in Google Android - CVE-2018-5886

Published: July 6, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36953
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-5886
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Google
Affected software:
Google Android

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

A pointer in an ADSPRPC command is not properly validated in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android), which can lead to kernel memory being accessed.


How to mitigate CVE-2018-5886

Install update from vendor's website.

Sources