CVE-2017-10996: Infoleak
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in cshow(), due to compathwcapstr[] not being NULL-terminated. This error is not fatal, however the device might crash/reboot with memory violation/out of bounds access.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates local access is required and user interaction is required. No privileges are required.
Which devices should be considered exposed?
The issue is described as affecting Qualcomm products running Android releases from CAF that use the Linux kernel. The provided information does not identify specific Android or kernel versions.
What is the likely security impact?
The issue can expose memory contents through an out-of-bounds access, reflected by a high confidentiality impact. The error is described as non-fatal, but it may cause a device crash or reboot.