PT-2018-1156 · Google+1 · Android+1
Published
2018-03-05
·
Updated
2019-10-03
·
CVE-2017-18069
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android for MSM versions (affected versions not specified)
QRD Android versions (affected versions not specified)
All Android releases from CAF using the Linux kernel versions (affected versions not specified)
Description
The issue is related to improper message length calculation in the
oem cmd handler() function while processing a WLAN NL MSG OEM netlink message, leading to a buffer overread. This can allow a remote attacker to disclose protected information using a specially crafted request.Recommendations
For Android for MSM, consider restricting access to the
oem cmd handler() function until a patch is available.
For QRD Android, avoid using the WLAN NL MSG OEM netlink message in the affected component until the issue is resolved.
For all Android releases from CAF using the Linux kernel, as a temporary workaround, consider disabling the WLAN component to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Android
Linux Kernel