CVE-2018-11987
CVE-2018-11987
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
20 Dec 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, if there is an unlikely memory alloc failure for the secure pool in boot, it can result in wrong pointer access causing kernel panic.
Affected products
Qualcomm, Inc. · Android for MSM, Firefox OS for MSM, QRD Android