First published: Mon Apr 02 2018(Updated: )
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, while processing the retransmission of WPA supplicant command send failures, there is a make after break of the connection to WPA supplicant where the local pointer is not properly updated. If the WPA supplicant command transmission fails, a Use After Free condition will occur.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm MSM8909W | ||
Qualcomm MSM8909W | ||
Qualcomm SD210 Firmware | ||
Qualcomm SD210 Firmware | ||
qualcomm SD 212 firmware | ||
qualcomm SD 212 | ||
Qualcomm 205 firmware | ||
Qualcomm 205 | ||
Qualcomm SD 450 Firmware | ||
Qualcomm SDM450 | ||
qualcomm sd 615 firmware | ||
qualcomm sd 615 | ||
Qualcomm Snapdragon 616 firmware | ||
Qualcomm Snapdragon 616 firmware | ||
qualcomm sd 415 firmware | ||
qualcomm sd 415 | ||
qualcomm SD 625 firmware | ||
qualcomm SD 625 | ||
qualcomm sd 650 firmware | ||
qualcomm sd 650 | ||
qualcomm sd 652 firmware | ||
qualcomm sd 652 | ||
qualcomm SD 820 firmware | ||
qualcomm SD 820 | ||
Qualcomm SD835 Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SD845 Firmware | ||
Qualcomm SD845 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18144 is considered a high-severity vulnerability affecting Android devices with specific Qualcomm chipsets.
To fix CVE-2017-18144, update your Android device to the security patch level of 2018-04-05 or later.
CVE-2017-18144 affects Android devices powered by Qualcomm Snapdragon chipsets, including models like SD 210, SD 450, and SD 845.
Yes, CVE-2017-18144 can potentially be exploited remotely due to the nature of the vulnerability in WPA supplicant command retransmissions.
Yes, CVE-2017-18144 has been addressed in the Android security patch updates released after April 2018.