CVE-2017-9677 Information
Feb 14, 2021
cve
Description
In all Qualcomm products with Android releases from CAF using the Linux kernel in function msm_compr_ioctl_shared variable \ddp-params_length\ could be accessed and modified by multiple threads while it is not protected with locks. If one thread is running while another thread is setting data race conditions will happen. If \ddp-params_length\ is set to a big number a buffer overflow will occur.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/100658 https://source.android.com/security/bulletin/2017-09-01
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: