CVE-2018-11264: Buffer Overflow
Possible buffer overflow in Ontario fingerprint code due to lack of input validation for the parameters coming into TZ from HLOS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11264?
CVE-2018-11264 is a vulnerability that could lead to a possible buffer overflow in Ontario fingerprint code due to lack of input validation for the parameters coming into TZ from HLOS in certain Qualcomm Snapdragon devices.
Which software versions are affected by CVE-2018-11264?
CVE-2018-11264 affects Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, and SD 450.
What is the severity level of CVE-2018-11264?
The severity of CVE-2018-11264 is rated as critical with a CVSS score of 7.8.
How can I fix CVE-2018-11264?
To fix CVE-2018-11264, users should apply the necessary software updates provided by Qualcomm or the device manufacturer.
Where can I find more information about CVE-2018-11264?
More information about CVE-2018-11264 can be found in the Android Security Bulletin for November 2018 and the SecurityFocus website.