CVE-2017-18124: Buffer Overflow
During secure boot, addition is performed on uint8 ptrs which led to overflow issue in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDX20
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18124?
CVE-2017-18124 is considered a high severity vulnerability due to potential exploitation allowing for secure boot bypass.
How do I fix CVE-2017-18124?
To fix CVE-2017-18124, users should update their affected Qualcomm firmware to the latest version released by the vendor.
Which products are affected by CVE-2017-18124?
CVE-2017-18124 affects multiple Qualcomm products including FSM9055, IPQ4019, and various Snapdragon chipsets.
What impact does CVE-2017-18124 have on devices?
The impact of CVE-2017-18124 may allow unauthorized firmware modifications and potential tampering with device security.
Is there a workaround for CVE-2017-18124?
Currently, there are no recommended workarounds for CVE-2017-18124 other than applying the appropriate firmware updates.