CVE-2017-18302: Race Condition
In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SnapdragonHighMed2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18302?
The severity of CVE-2017-18302 is high with a severity value of 4.7.
How can I fix the vulnerability in CVE-2017-18302?
To fix the vulnerability in CVE-2017-18302, ensure that you have installed the latest security updates and patches provided by the vendor.
Which software versions are affected by CVE-2017-18302?
CVE-2017-18302 affects Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016.
What is the Common Weakness Enumeration (CWE) ID for CVE-2017-18302?
The Common Weakness Enumeration (CWE) ID for CVE-2017-18302 is 362.
Where can I find more information about CVE-2017-18302?
You can find more information about CVE-2017-18302 in the official Google Android security bulletin for August 2018.