CVE-2017-10997: Buffer Overflow
Published Sep 5, 2017
·Updated
In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node, a write to a PCIe register can cause corruption of kernel memory.
Affected Software
2 affected components
Google Android<=8.0
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 21, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local attack access with no privileges required, but user interaction is required. The impact can include high confidentiality, integrity, and availability compromise.
2
Which environments are in scope?
The issue is described as affecting Qualcomm products with Android releases from CAF that use the Linux kernel. The provided data identifies Google Android as the software.
3
What component is involved in the vulnerability?
The vulnerability involves a debugfs node that permits a write to a PCIe register, which can corrupt kernel memory. It is classified as a buffer overflow.