CVE-2018-5861: Google Android
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, existing checks in place on partition size are incomplete and can lead to heap overwrite vulnerabilities while loading a secure application from the boot loader.
Affected products
- Google Android: affected versions not specified
Published 2018-11-27. Last modified 2026-06-17.