CVE-2018-11967: High severity android vulnerability
Signature verification of the skel library could potentially be disabled as the memory region on the remote subsystem in which the library is loaded is allocated from userspace currently in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, Qualcomm 215, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SDX24
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-11967?
CVE-2018-11967 is a vulnerability related to the skel library in certain Qualcomm products.
What is the severity of CVE-2018-11967?
CVE-2018-11967 has a severity rating of 7.8 out of 10, which is considered high.
Which products are affected by CVE-2018-11967?
CVE-2018-11967 affects Qualcomm products such as Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial I, and others.
How can I fix CVE-2018-11967?
To fix CVE-2018-11967, it is recommended to apply the necessary security patches provided by Qualcomm or the relevant device manufacturer.
Where can I find more information about CVE-2018-11967?
You can find more information about CVE-2018-11967 in the April 2019 Code Aurora Security Bulletin and the Android Security Bulletin for April 2019.