CVE-2014-0973: High severity little kernel vulnerability
The imageverify function in platform/msmshared/imageverify.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not check whether a certain digest size is consistent with the RSApublicdecrypt API specification, which makes it easier for attackers to bypass boot-image authentication requirements via trailing data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0973?
CVE-2014-0973 is rated as a high severity vulnerability due to potential exploitation that could allow attackers to bypass signature verification.
How do I fix CVE-2014-0973?
To fix CVE-2014-0973, update to a patched version of the Little Kernel bootloader that addresses the digest size checking issue.
What types of devices are affected by CVE-2014-0973?
CVE-2014-0973 affects devices utilizing the Little Kernel bootloader distributed with Qualcomm Innovation Center Android contributions for MSM devices.
What are the potential impacts of CVE-2014-0973?
The potential impacts of CVE-2014-0973 include unauthorized access and execution of malicious code due to inadequate signature verification.
Who is impacted by CVE-2014-0973?
Users of devices running vulnerable versions of the Little Kernel bootloader are impacted by CVE-2014-0973.