#VU12262 Uncontrolled memory allocation in Linux kernel - CVE-2017-9725

 

#VU12262 Uncontrolled memory allocation in Linux kernel - CVE-2017-9725

Published: April 27, 2018


Vulnerability identifier: #VU12262
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2017-9725
CWE-ID: CWE-789
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Linux kernel
Software vendor:
Linux Foundation

Description

The vulnerability allows a local attacker to case DoS condition or gain elevated privileges on the target system.

The weakness exists in all Qualcomm products with Android releases from CAF during DMA allocation due to wrong data type of size allocation size gets truncated which makes allocation succeed when it should fail. A local attacker can cause the service to crash or gain root privileges.

Remediation

Update to version 4.5.

External links