PT-2017-19115 · Qualcomm+3 · Qrd Android+3

Published

2017-10-10

·

Updated

2017-10-19

·

CVE-2017-9686

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android for MSM (affected versions not specified) Firefox OS for MSM (affected versions not specified) QRD Android (affected versions not specified)
Description The issue is related to a possible double free or use after free in the SPS driver when debugfs logging is used. This affects Android releases from CAF that utilize the Linux kernel.
Recommendations For Android for MSM, consider disabling debugfs logging as a temporary workaround until a patch is available. For Firefox OS for MSM, restrict access to the SPS driver to minimize the risk of exploitation. For QRD Android, avoid using the SPS driver with debugfs logging enabled until the issue is resolved.

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9686

Affected Products

Android
Firefox Os
Linux Kernel
Qrd Android