CVE-2018-5907: Google Android
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Possible buffer overflow in msm_adsp_stream_callback_put due to lack of input validation of user-provided data that leads to integer overflow in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
Affected products
- Google Android: up to and including 8.1
Published 2018-07-06. Last modified 2026-06-17.