SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-13918

kernel could return a received message length higher than expected, which leads to buffer overflow in a subsequent operation and stops normal operation in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon…

HIGH 7.8EPSS 0.23%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

kernel could return a received message length higher than expected, which leads to buffer overflow in a subsequent operation and stops normal operation in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 675, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM439, SDX24, SM7150

CVSS 3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.23% probability · 13th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
qualcomm/mdm9150 firmware · qualcomm/mdm9206 firmware · qualcomm/mdm9607 firmware · qualcomm/mdm9650 firmware · qualcomm/msm8909w firmware · qualcomm/qcs605 firmware · qualcomm/qm215 firmware · qualcomm/sd 425 firmware · qualcomm/sd 439 firmware · qualcomm/sd 429 firmware · qualcomm/sd 450 firmware · qualcomm/sd 625 firmware · qualcomm/sd 632 firmware · qualcomm/sd 675 firmware · qualcomm/sd 712 firmware · qualcomm/sd 710 firmware · qualcomm/sd 670 firmware · qualcomm/sd 820a firmware · qualcomm/sd 835 firmware · qualcomm/sd 845 firmware · +5 more
Source
product-security@qualcomm.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.