CVE-2017-18274: Out-of-bounds Read
While iterating through the models contained in a fixed-size array in the actData structure, which also stores an incorrect number of models that is greater than the size of the array, a buffer overflow occurs in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 820, SD 820A, SD 835
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18274?
CVE-2017-18274 has a high severity level due to the potential for remote code execution.
How do I fix CVE-2017-18274?
To fix CVE-2017-18274, update to the latest firmware version provided by Qualcomm for the affected devices.
Which devices are affected by CVE-2017-18274?
CVE-2017-18274 affects various models including Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear, specifically in MDM9206, MDM9607, and MDM9650.
What is a buffer overflow as related to CVE-2017-18274?
In the context of CVE-2017-18274, a buffer overflow occurs when the actData structure iterates through a fixed-size array, potentially exceeding its bounds due to incorrect model counts.
Is CVE-2017-18274 publicly known?
Yes, CVE-2017-18274 is publicly known and documented as a vulnerability affecting Qualcomm products.