CVE-2018-5890 describes a high-severity vulnerability affecting Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before the 2018-06-05 security patch level. The flaw allows an attacker to bypass a device tree validity check if the fdt_totalsize is reported as zero, potentially leading to arbitrary code execution, information disclosure, and denial of service. With a CVSS score of 7.8, this vulnerability has low attack complexity and requires local privileges, but there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.