CVE-2014-9866: Input Validation
drivers/media/platform/msm/camerav2/sensor/csid/msmcsid.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate a certain parameter, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28747684 and Qualcomm internal bug CR511358.
Affected Software
Remediation
Event History
Frequently Asked Questions
Which devices are identified as affected?
The issue is identified in Qualcomm components on Nexus 5 and Nexus 7 (2013) devices running Android versions before 2016-08-05.
What does an attacker need to exploit this issue?
An attacker can exploit the issue using a crafted application. The CVSS vector indicates local access, no privileges required, and user interaction is required.
What is the potential impact of successful exploitation?
Successful exploitation can allow an attacker to gain privileges. The CVSS metrics indicate high potential impact to confidentiality, integrity, and availability.
Is a fix available?
Yes. A patch is available for this input-validation issue in the Qualcomm camera CSID driver component.