CVE-2017-18171: Input Validation
Improper input validation for GATT data packet received in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 835, SD 845, SD 850, SDM630, SDM636, SDM660, SDM710, SnapdragonHighMed2016.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18171?
CVE-2017-18171 has a medium severity due to potential memory corruption issues in affected Qualcomm hardware.
How do I fix CVE-2017-18171?
Mitigation for CVE-2017-18171 can typically be achieved through firmware updates provided by Qualcomm.
Which Qualcomm devices are affected by CVE-2017-18171?
CVE-2017-18171 affects several Snapdragon Mobile versions, including QCA9379 and various SD series models like SD 210, SD 425, and SD 835.
Is the memory corruption from CVE-2017-18171 exploitable?
Yes, the improper input validation in CVE-2017-18171 can potentially be exploited to cause memory corruption.
What products are vulnerable to CVE-2017-18171?
Among the vulnerable products, Qualcomm's QCA9379 and Snapdragon SD series like SD 410 and SD 820 are significant examples.