CVE-2017-18145: Use After Free
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, while the DPM native process is processing framework events, the iterator pointer is deleted after processing an event. When processing subsequent events, a Use After Condition will occur.
Affected Software
Event History
Frequently Asked Questions
Which devices are within the stated affected hardware scope?
The issue applies to Android devices using the listed Qualcomm Snapdragon Mobile and Snapdragon Wear platforms: MSM8909W, SD 210, SD 212, SD 205, SD 450, SD 615, SD 616, SD 415, SD 625, SD 650, SD 652, SD 820, SD 835, and SD 845. Android devices before the 2018-04-05 security patch level are affected within that scope.
Does exploitation require an authenticated account or user interaction?
No. The supplied CVSS vector indicates network attack access with low attack complexity, no privileges required, and no user interaction required.
What security impact is indicated if the vulnerability is exploited?
The CVSS vector rates confidentiality, integrity, and availability impact as high. The vulnerability occurs in the DPM native process when subsequent framework events are handled after an iterator pointer has been deleted.