CVE-2017-18144: Use After Free
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, while processing the retransmission of WPA supplicant command send failures, there is a make after break of the connection to WPA supplicant where the local pointer is not properly updated. If the WPA supplicant command transmission fails, a Use After Free condition will occur.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18144?
CVE-2017-18144 is considered a high-severity vulnerability affecting Android devices with specific Qualcomm chipsets.
How do I fix CVE-2017-18144?
To fix CVE-2017-18144, update your Android device to the security patch level of 2018-04-05 or later.
What type of devices are affected by CVE-2017-18144?
CVE-2017-18144 affects Android devices powered by Qualcomm Snapdragon chipsets, including models like SD 210, SD 450, and SD 845.
Can CVE-2017-18144 be exploited remotely?
Yes, CVE-2017-18144 can potentially be exploited remotely due to the nature of the vulnerability in WPA supplicant command retransmissions.
Is CVE-2017-18144 fixed in recent Android updates?
Yes, CVE-2017-18144 has been addressed in the Android security patch updates released after April 2018.