UBUNTU-CVE-2018-11832

Source
https://ubuntu.com/security/CVE-2018-11832
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-11832.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-11832
Upstream
  • CVE-2018-11832
Withdrawn
2025-07-18T16:44:37Z
Published
2018-09-18T18:29:00Z
Modified
2025-07-16T07:37:50.145366Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - low
Summary
[none]
Details

In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, lack of input size validation before copying to buffer in PMIC function can lead to heap overflow.

References

Affected packages

Ubuntu:14.04:LTS / linux-azure

Package

Name
linux-azure
Purl
pkg:deb/ubuntu/linux-azure@4.15.0-1023.24~14.04.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15.0-1023.24~14.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-azure-cloud-tools-4.15.0-1023"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-azure-cloud-tools-4.15.0-1023-dbgsym"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-azure-headers-4.15.0-1023"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-azure-tools-4.15.0-1023"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-azure-tools-4.15.0-1023-dbgsym"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-cloud-tools-4.15.0-1023-azure"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-headers-4.15.0-1023-azure"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-image-unsigned-4.15.0-1023-azure"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-image-unsigned-4.15.0-1023-azure-dbgsym"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-modules-4.15.0-1023-azure"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-modules-extra-4.15.0-1023-azure"
        },
        {
            "binary_version": "4.15.0-1023.24~14.04.1",
            "binary_name": "linux-tools-4.15.0-1023-azure"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-11832.json"