CVE-2017-0553: Integer Overflow
An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32342065. NOTE: this issue also exists in the upstream libnl before 3.3.0 library.
Other sources
An integer overflow vulnerability was found in nlmsgreserve() triggered by crafted @len argument resulting into reserving too few bytes.
Upstream patch:
http://git.infradead.org/users/tgr/libnl.git/commit/3e18948f17148e6a3c4255bdeaaf01ef6081ceeb
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0553?
CVE-2017-0553 is rated as Moderate because it requires compromising a privileged process.
How do I fix CVE-2017-0553?
To fix CVE-2017-0553, update the libnl package to the latest version as specified in your distribution's security advisory.
Which versions of Android are affected by CVE-2017-0553?
CVE-2017-0553 affects Android versions 5.0 through 7.1.1.
Can CVE-2017-0553 be exploited remotely?
CVE-2017-0553 requires local access for exploitation, as it needs to compromise a privileged process.
What component is vulnerable in CVE-2017-0553?
The vulnerability CVE-2017-0553 is found in the libnl library used in Wi-Fi services.