Race condition in Google Android - CVE-2018-5845

 

Race condition in Google Android - CVE-2018-5845

Published: June 6, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37080
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5845
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

A race condition in drm_atomic_nonblocking_commit() in the display driver can potentially lead to a Use After Free scenario in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.


Affected software

Google Android

How to mitigate CVE-2018-5845

Install update from vendor's website.


External References

Related Security Bulletins