CVE-2018-5891
—CVSS 3.0
8.4 high
EPSS
<1%p13
Published
()
Modified
Description
While processing modem SSR after IMS is registered, the IMS data daemon is restarted but the ipc_dataHandle is no longer available. Consequently, the DPL thread frees the internal memory for dataDHandle but the local variable pointer is not updated which can lead to a Use After Free condition in Snapdragon Mobile and Snapdragon Wear.
- Vendors
- qualcomm
- Products
- msm8909w firmware, msm8996au firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 450 firmware, sd 615 firmware, sd 616 firmware, sd 415 firmware, sd 625 firmware, sd 650 firmware, sd 652 firmware
- Weakness
- CWE-416
- Vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.