CVE-2018-5873

An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05.
Configurations

Configuration 1 (hide)

cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:09

Type Values Removed Values Added
References () http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=073c516ff73557a8f7315066856c04b50383ac34 - Patch, Third Party Advisory () http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=073c516ff73557a8f7315066856c04b50383ac34 - Patch, Third Party Advisory
References () https://github.com/torvalds/linux/commit/073c516ff73557a8f7315066856c04b50383ac34 - Patch, Third Party Advisory () https://github.com/torvalds/linux/commit/073c516ff73557a8f7315066856c04b50383ac34 - Patch, Third Party Advisory
References () https://source.android.com/security/bulletin/2018-07-01 - Vendor Advisory () https://source.android.com/security/bulletin/2018-07-01 - Vendor Advisory
References () https://source.codeaurora.org/quic/la/kernel/msm-4.9/commit/?id=34742aaf7cb16c95edba4a7afed6d2c4fa7e434b - Third Party Advisory () https://source.codeaurora.org/quic/la/kernel/msm-4.9/commit/?id=34742aaf7cb16c95edba4a7afed6d2c4fa7e434b - Third Party Advisory
References () https://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-security-bulletin - Third Party Advisory () https://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-security-bulletin - Third Party Advisory

19 Jul 2023, 00:53

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Information

Published : 2018-07-06 19:29

Updated : 2024-11-21 04:09


NVD link : CVE-2018-5873

Mitre link : CVE-2018-5873

CVE.ORG link : CVE-2018-5873


JSON object : View

Products Affected

google

  • android

linux

  • linux_kernel
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-416

Use After Free