PT-2017-19115 · Qualcomm+3 · Qrd Android+3
Publicado
2017-10-10
·
Atualizado
2017-10-19
·
CVE-2017-9686
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android for MSM (affected versions not specified)
Firefox OS for MSM (affected versions not specified)
QRD Android (affected versions not specified)
Description
The issue is related to a possible double free or use after free in the SPS driver when debugfs logging is used. This affects Android releases from CAF that utilize the Linux kernel.
Recommendations
For Android for MSM, consider disabling debugfs logging as a temporary workaround until a patch is available.
For Firefox OS for MSM, restrict access to the SPS driver to minimize the risk of exploitation.
For QRD Android, avoid using the SPS driver with debugfs logging enabled until the issue is resolved.
Correção
Double Free
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Android
Firefox Os
Linux Kernel
Qrd Android