CVE-2017-10998 Information
Feb 14, 2021
cve
Description
In all Qualcomm products with Android releases from CAF using the Linux kernel in audio_aio_ion_lookup_vaddr the buffer length which is user input ends up being used to validate if the buffer is fully within the valid region. If the buffer length is large enough then the address + length operation could overflow and produce a result far below the valid region.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/100658 https://source.android.com/security/bulletin/2017-09-01
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: