CVE-2018-11304: Google Android

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

Affected products

  • Google Android: up to and including 8.1

Published 2018-07-06. Last modified 2026-06-17.