PT-2017-18232 · Google+1 · Android+1
Published
2017-05-12
·
Updated
2020-11-09
·
CVE-2017-8244
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions prior to a fixed version (affected versions not specified)
Description
The issue affects the core info read and inst info read functions in Android releases using the Linux kernel. Variables
dbg buf, dbg buf->curr, and dbg buf->filled size can be modified by different threads simultaneously without protection from mutex or locks, leading to potential buffer overflow on race conditions. The buffer->curr variable itself can also be overwritten, allowing it to point to any location in kernel memory for writing.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Linux Kernel