Due to a race condition in a camera driver ioctl handler in Android releases from CAF using the linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-06-05, a Use After Free condition can occur.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
https://www.codeaurora.org/security-bulletin/2018/07/02/july-2018-code-aurora-security-bulletin | third party advisory |
https://source.android.com/security/bulletin/pixel/2018-06-01#qualcomm-components | third party advisory |