PT-2018-6820 · Qualcomm · Snapdragon+1

Published

2018-09-20

·

Updated

2018-11-23

·

CVE-2017-18301

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Small Cell SoC and Snapdragon (Automobile, Mobile, Wear) versions FSM9055, FSM9955, MDM9607, MDM9640, MDM9650, MSM8909W, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SDM630, SDM636, SDM660, SDX20, Snapdragon High Med 2016
Description: The issue arises when the NULL argument of the ICE regulator is provided while processing the create key IOCTL, resulting in a system restart.
Recommendations: For versions FSM9055, FSM9955, MDM9607, MDM9640, MDM9650, MSM8909W, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SDM630, SDM636, SDM660, SDX20, Snapdragon High Med 2016, consider avoiding the use of the NULL argument for the ICE regulator when processing the create key IOCTL to prevent system restarts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-18301

Affected Products

Small Cell Soc
Snapdragon