CVE-2018-5855: Google Android
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
While padding or shrinking a nested wmi packet in all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05, a buffer over-read can potentially occur.
Affected products
- Google Android: affected versions not specified
Published 2018-07-06. Last modified 2026-06-17.