CVE-2017-18277: Medium severity Google Android vulnerability
When dynamic memory allocation fails, currently the process sleeps for one second and continues with infinite loop without retrying for memory allocation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCN5502, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18277?
CVE-2017-18277 is a vulnerability that occurs when dynamic memory allocation fails in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in versions MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCN5502, SD 210/SD 212/SD 205/SD 425/SD 430/SD 450/SD 600/SD 615/SD 616/SD 415/SD 625/SD 650/SD 652/SD 810/SD 820/SD 820a/SD 835, allowing the process to sleep for one second and continue with an infinite loop without retrying for memory allocation.
How severe is CVE-2017-18277?
CVE-2017-18277 has a severity rating of 5.5 out of 10, which is considered high.
Which software versions are affected by CVE-2017-18277?
CVE-2017-18277 affects Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in versions MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, QCN5502, SD 210/SD 212/SD 205/SD 425/SD 430/SD 450/SD 600/SD 615/SD 616/SD 415/SD 625/SD 650/SD 652/SD 810/SD 820/SD 820a/SD 835.
How do I fix CVE-2017-18277?
To fix CVE-2017-18277, it is recommended to update your devices to the latest available firmware or software version provided by the respective vendor or manufacturer.
Where can I find more information about CVE-2017-18277?
More information about CVE-2017-18277 can be found in the Android Security Bulletin for July 2018, specifically in the Qualcomm closed-source components section.