PT-2017-19115 · Qualcomm+3 · Qrd Android+3
Published
2017-10-10
·
Updated
2017-10-19
·
CVE-2017-9686
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Android for MSM (affected versions not specified)
Firefox OS for MSM (affected versions not specified)
QRD Android (affected versions not specified)
Description
The issue is related to a possible double free or use after free in the SPS driver when debugfs logging is used. This affects Android releases from CAF that utilize the Linux kernel.
Recommendations
For Android for MSM, consider disabling debugfs logging as a temporary workaround until a patch is available.
For Firefox OS for MSM, restrict access to the SPS driver to minimize the risk of exploitation.
For QRD Android, avoid using the SPS driver with debugfs logging enabled until the issue is resolved.
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Firefox Os
Linux Kernel
Qrd Android