CVE-2018-11840: Google Android
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing the WLAN driver command ioctl a temporary buffer used to construct the reply message may be freed twice.
Affected products
- Google Android: affected versions not specified
Published 2018-09-18. Last modified 2026-06-17.