Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-5856

Опубликовано: 03 дек. 2018
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, due to a race condition, a Use After Free condition can occur in Audio.

The Linux kernel is vulnerable to a use-after-free in sound/soc/qcom/qdsp6/q6asm.c due to a race condition. An attacker could exploit this to cause a kernel panic or other potential unspecified impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise MRG 2kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1655386kernel: Use-after-free in sound/soc/qcom/qdsp6/q6asm.c allows for kernel panic

EPSS

Процентиль: 18%
0.00058
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
около 7 лет назад

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, due to a race condition, a Use After Free condition can occur in Audio.

CVSS3: 7.8
github
больше 3 лет назад

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, due to a race condition, a Use After Free condition can occur in Audio.

EPSS

Процентиль: 18%
0.00058
Низкий

5.5 Medium

CVSS3