CVE-2017-18298: Null Pointer Dereference
Lack of Input Validation in SDMX API can lead to NULL pointer access in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660 .
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18298?
CVE-2017-18298 is a vulnerability that allows for NULL pointer access in Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear devices running certain Qualcomm firmware versions.
Which devices are affected by CVE-2017-18298?
Devices from Qualcomm, such as MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, and SD 820, may be affected by CVE-2017-18298.
What is the severity of CVE-2017-18298?
CVE-2017-18298 has a severity rating of 7.8 (high).
How can I fix CVE-2017-18298?
To fix CVE-2017-18298, it is recommended to update the affected Qualcomm firmware to a version that addresses the vulnerability.
Where can I find more information about CVE-2017-18298?
You can find more information about CVE-2017-18298 in the Android Security Bulletin for August 2018 and the SecurityTracker website.