PT-2018-6654 · Linux · Linux Kernel

Published

2018-06-12

·

Updated

2018-08-01

·

CVE-2017-18070

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Linux Kernel (affected versions not specified)
Description: The issue arises in the wma ndp end response event handler() function, where the len end rsp variable, a uint32, can be overflowed if the value of the variable event->num ndp end rsp per ndi list is very large. This overflow can lead to a heap overwrite of the end rsp heap object. The problem affects all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) that use the Linux Kernel.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18070

Affected Products

Linux Kernel