Integer overflow in Google Android - CVE-2017-17765

 

Integer overflow in Google Android - CVE-2017-17765

Published: February 24, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37497
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17765
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to execute arbitrary code.

In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in wma_get_ll_stats_ext_buf() and are used to allocate the sizes of buffers and may be vulnerable to integer overflow leading to buffer overflow.


Affected software

Google Android

How to mitigate CVE-2017-17765

Install update from vendor's website.


External References

Related Security Bulletins