CVE-2018-5824
Description
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while processing HTT_T2H_MSG_TYPE_RX_FLUSH or HTT_T2H_MSG_TYPE_RX_PN_IND messages, a buffer overflow can occur if the tid value obtained from the firmware is out of range.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer overflow in Qualcomm Wi-Fi driver allows remote code execution via out-of-range TID values in firmware messages.
Vulnerability
A buffer overflow exists in the Qualcomm Wi-Fi driver processing HTT_T2H_MSG_TYPE_RX_FLUSH or HTT_T2H_MSG_TYPE_RX_PN_IND messages. The vulnerability occurs when the tid value obtained from firmware is out of range, leading to a buffer overflow. This affects Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05 [1].
Exploitation
An attacker requires proximity to the victim device to send crafted Wi-Fi frames. The attacker needs to be within Wi-Fi range and send a specially crafted message with an out-of-range tid value. No authentication is required as the vulnerability is in the firmware message parsing path before any access control checks [1].
Impact
Successful exploitation leads to a buffer overflow, which can cause memory corruption and potentially allow arbitrary code execution in the context of the Wi-Fi driver. This could result in a complete compromise of the device's Wi-Fi subsystem and enable further privilege escalation [1].
Mitigation
The issue was fixed in the Android security patch level 2018-04-05. Users should ensure their devices receive this or later security updates. For Pixel/Nexus devices, the fix was included in the April 2018 security bulletin. There is no workaround besides applying the vendor-supplied patch [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Qualcomm, Inc./Android for MSM, Firefox OS for MSM, QRD Androidv5Range: All Android releases from CAF using the Linux kernel
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- source.android.com/security/bulletin/pixel/2018-04-01mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.