CVE-2017-18144: Use After Free

Published Apr 2, 2018
·
Updated

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, while processing the retransmission of WPA supplicant command send failures, there is a make after break of the connection to WPA supplicant where the local pointer is not properly updated. If the WPA supplicant command transmission fails, a Use After Free condition will occur.

Affected Software

29 affected components
Google Android
Qualcomm Msm8909w Firmware
Qualcomm MSM8909W
Qualcomm Sd 210 Firmware
Qualcomm SD 210
Qualcomm Sd 212 Firmware
Qualcomm SD 212
Qualcomm Sd 205 Firmware
Qualcomm SD 205
Qualcomm Sd 450 Firmware
Qualcomm SD 450
Qualcomm Sd 615 Firmware
Qualcomm SD 615
Qualcomm Sd 616 Firmware
Qualcomm Sd 616
Qualcomm Sd 415 Firmware
Qualcomm SD 415
Qualcomm Sd 625 Firmware
Qualcomm SD 625
Qualcomm Sd 650 Firmware
Qualcomm SD 650
Qualcomm Sd 652 Firmware
Qualcomm Sd 652
Qualcomm Sd 820 Firmware
Qualcomm SD 820
Qualcomm Sd 835 Firmware
Qualcomm SD 835
Qualcomm Sd 845 Firmware
Qualcomm SD 845

Event History

Apr 2, 2018
CVE Published
via Android·12:00 AM
Apr 11, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness

Frequently Asked Questions

1

What is the severity of CVE-2017-18144?

CVE-2017-18144 is considered a high-severity vulnerability affecting Android devices with specific Qualcomm chipsets.

2

How do I fix CVE-2017-18144?

To fix CVE-2017-18144, update your Android device to the security patch level of 2018-04-05 or later.

3

What type of devices are affected by CVE-2017-18144?

CVE-2017-18144 affects Android devices powered by Qualcomm Snapdragon chipsets, including models like SD 210, SD 450, and SD 845.

4

Can CVE-2017-18144 be exploited remotely?

Yes, CVE-2017-18144 can potentially be exploited remotely due to the nature of the vulnerability in WPA supplicant command retransmissions.

5

Is CVE-2017-18144 fixed in recent Android updates?

Yes, CVE-2017-18144 has been addressed in the Android security patch updates released after April 2018.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203