Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5848

Опубликовано: 12 июн. 2018
Источник: debian
EPSS Низкий

Описание

In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.16.5-1package
linuxfixed4.9.144-1stretchpackage

Примечания

  • Fixed by: https://git.kernel.org/linus/b5a8ffcae4103a9d823ea3aa3a761f65779fbe2a (4.16-rc1)

EPSS

Процентиль: 35%
0.0014
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVSS3: 5.3
redhat
больше 7 лет назад

In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVSS3: 7.8
nvd
около 7 лет назад

In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

suse-cvrf
больше 6 лет назад

Security update for the Linux Kernel (Live Patch 7 for SLE 12 SP3)

suse-cvrf
больше 6 лет назад

Security update for the Linux Kernel (Live Patch 18 for SLE 12 SP2)

EPSS

Процентиль: 35%
0.0014
Низкий
Уязвимость CVE-2018-5848