« Volver al listado

CVE-2018-5848

Estado: ModificadaAlta (7.8)—

In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (6)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-5848",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@qualcomm.com",
      "affectedData": [
        {
          "vendor": "Qualcomm, Inc.",
          "product": "Android for MSM, Firefox OS for MSM, QRD Android",
          "versions": [
            {
              "status": "affected",
              "version": "All Android releases from CAF using the Linux kernel"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-06-12T20:29:00.983",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:2948",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@qualcomm.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:3083",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@qualcomm.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:3096",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "product-security@qualcomm.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "product-security@qualcomm.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "product-security@qualcomm.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "product-security@qualcomm.com"
    },
    {
      "url": "https://www.codeaurora.org/security-bulletin/2018/05/11/may-2018-code-aurora-security-bulletin-2",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "product-security@qualcomm.com"
    },
    {
      "url": "https://source.android.com/security/bulletin/pixel/2018-05-01",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "nvd@nist.gov"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:2948",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:3083",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2018:3096",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2019/03/msg00017.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2019/03/msg00034.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2019/04/msg00004.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.codeaurora.org/security-bulletin/2018/05/11/may-2018-code-aurora-security-bulletin-2",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        },
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel."
    },
    {
      "lang": "es",
      "value": "En la función wmi_set_ie(), el código de validación de longitud no gestiona correctamente los desbordamientos de enteros sin firmar. Como resultado, un gran valor del argumento \"ie_len\" puede provocar un desbordamiento de búfer en todas las distribuciones de Android de CAF (Android for MSM, Firefox OS for MSM, QRD Android) que utilizan el kernel de Linux."
    }
  ],
  "lastModified": "2026-06-17T02:00:53.487",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:google:android:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8B9FEC8-73B6-43B8-B24E-1F7C20D91D26"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB28F9AF-3D06-4532-B397-96D7E4792503"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33C068A4-3780-4EAB-A937-6082DF847564"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51EF4996-72F4-4FA4-814F-F5991E7A8318"
            },
            {
              "criteria": "cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "825ECE2D-E232-46E0-A047-074B34DB1E97"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@qualcomm.com"
}