Out-of-Bounds Access in Android GNSS Configurations by Qualcomm
CVE-2018-11961
7.8HIGH
What is CVE-2018-11961?
A vulnerability exists in the Android operating system across multiple releases that utilize the Qualcomm-based Linux kernel. This flaw allows an attacker to potentially access an out-of-bounds vector index when certain GNSS (Global Navigation Satellite System) configurations are updated. This can lead to unexpected behavior and may compromise device integrity or access sensitive data.
Affected Version(s)
Android for MSM, Firefox OS for MSM, QRD Android All Android releases from CAF using the Linux kernel