CVE-2018-5848
published 2018-06-12CVE-2018-5848: In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len'…
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.37%
29.2th percentile
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 4.16.5-1 (bookworm) | linux 4.16.5-1 (bookworm) |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| linux | linux_kernel | >= 0 < 4.16.5-1 | 4.16.5-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | virtualization_host | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2018-5848: linux - In the function wmi_set_ie(), the length validation code does not handle unsigne...
vendor_debian·2018·CVSS 7.8
CVE-2018-5848 [HIGH] CVE-2018-5848: linux - In the function wmi_set_ie(), the length validation code does not handle unsigne...
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
Scope: local
bookworm: resolved (fixed in 4.16.5-1)
bullseye: resolved (fixed in 4.16.5-1)
forky: resolved (fixed in 4.16.5-1)
sid: resolved (fixed in 4.16.5-1)
trixie: resolved (fixed in 4.16.5-1)
Red Hat
kernel: buffer overflow in drivers/net/wireless/ath/wil6210/wmi.c:wmi_set_ie() may lead to memory corruption
vendor_redhat·2017-12-02·CVSS 7.8
CVE-2018-5848 [HIGH] CWE-120 kernel: buffer overflow in drivers/net/wireless/ath/wil6210/wmi.c:wmi_set_ie() may lead to memory corruption
kernel: buffer overflow in drivers/net/wireless/ath/wil6210/wmi.c:wmi_set_ie() may lead to memory corruption
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
In the function wmi_set_ie() in the Linux kernel the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the ‘ie_len’ argument can cause a buffer overflow and thus a memory corruption leading to a system crash or other or unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believ
GHSA
GHSA-hf9h-mjmm-hjj4: In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly
ghsa_unreviewed·2022-05-14
CVE-2018-5848 [HIGH] CWE-119 GHSA-hf9h-mjmm-hjj4: In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
OSV
CVE-2018-5848: In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly
osv·2018-06-12·CVSS 7.8
CVE-2018-5848 [HIGH] CVE-2018-5848: In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2018:2948https://access.redhat.com/errata/RHSA-2018:3083https://access.redhat.com/errata/RHSA-2018:3096https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlhttps://www.codeaurora.org/security-bulletin/2018/05/11/may-2018-code-aurora-security-bulletin-2https://source.android.com/security/bulletin/pixel/2018-05-01https://access.redhat.com/errata/RHSA-2018:2948https://access.redhat.com/errata/RHSA-2018:3083https://access.redhat.com/errata/RHSA-2018:3096https://lists.debian.org/debian-lts-announce/2019/03/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2019/03/msg00034.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00004.htmlhttps://www.codeaurora.org/security-bulletin/2018/05/11/may-2018-code-aurora-security-bulletin-2
2018-06-12
Published