CVE-2017-5625: Null Pointer Dereference
In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') by issuing the 'fastboot oem dump <partition>' fastboot command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5625?
CVE-2017-5625 is considered a high severity vulnerability that allows an unauthorized attacker to partially dump the contents of an arbitrary partition on affected devices.
How do I fix CVE-2017-5625?
To fix CVE-2017-5625, update your OnePlus 3 or 3T device to OxygenOS version 4.0.3 or later.
Which devices are affected by CVE-2017-5625?
CVE-2017-5625 affects OnePlus 3 and OnePlus 3T devices running OxygenOS versions up to 4.0.2.
What can an attacker achieve with CVE-2017-5625?
An attacker can use CVE-2017-5625 to dump the ciphertext content of arbitrary partitions from devices with a locked bootloader, except for the 'keystore' partition.
Is there a workaround for CVE-2017-5625?
Currently, the recommended action for CVE-2017-5625 is to upgrade to a patched version of the OxygenOS, as there are no known effective workarounds.