Vulnerability

CVE-2018-11288

Component: TRUST
Possible undefined behavior due to lack of size check in function for parameter segment_idx can lead to a read outside of the intended region in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDX24, SXR1130

Impact

Severity (Manufact.)

N/A

Severity (NIST)

7.8

Severity (Android)

N/A

Chipsets

12

Devices

666

Affected Hardware

NameAlso known asManufacturer
MSM8909
Snapdragon 210
Qualcomm
MSM8909AA
Snapdragon 212
Qualcomm
MSM8916
Snapdragon 410
Qualcomm
SDM670
Snapdragon 670
Qualcomm
SDM710
Snapdragon 710
Qualcomm
SDM712
Snapdragon 712
Qualcomm
MSM8996Lite
Snapdragon 820
Qualcomm
MSM8996
Snapdragon 820
Qualcomm
MSM8998
Snapdragon 835
Snapdragon 835 Mobile PC Platform
Qualcomm
SDM845
Snapdragon 845
Qualcomm
12 of 12 row(s) shown.

Rows per page

Page 1 of 2

Timeline

Introduced (est):
Jan 1, 2014
Reported:
Unknown
Advisory Published:
Dec 3, 2018
CVE Published:
Jan 18, 2019
Android Patch Level:
None
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter