CVE-2018-11262 PUBLISHED CVSS 7.199999809265137 HIGH

In Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel while trying to find out total number of partition via a non zero check, there could be possibility where the 'TotalPart' could cross 'GptHeader->MaxPtCnt' and which could result in OOB write in patching GPT.

EPSS 0.03% · 9.1th percentile

Risk Scores

CVSS v2.0
7.199999809265137
EPSS Score
0.03%
9.1th percentile

Affected Products

VendorProductVersions
Qualcomm, Inc.Android for MSM, Firefox OS for MSM, QRD AndroidAll Android releases from CAF using the Linux kernel
googleandroid

Timeline

References

Open in Interactive Console →