Null Pointer Dereference in Android Releases by Qualcomm
CVE-2018-12014
7.8HIGH
Summary
A null pointer dereference vulnerability exists in all Android releases leveraging Qualcomm's MSM, including Firefox OS and QRD Android. This flaw is caused by a missing NULL assignment in the NAT module of a freed pointer, which could lead to undefined behavior and potential system disruption. It is crucial for users and administrators of affected devices to remain informed about this vulnerability and implement any available patches or mitigations.
Affected Version(s)
Android for MSM, Firefox OS for MSM, QRD Android All Android releases from CAF using the Linux kernel
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved