CVE-2017-8149: Buffer Overflow
The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an out-of-bounds memory access vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. the APP can modify specific data to cause buffer overflow in the next system reboot, causing out-of-bounds memory read which can continuous system reboot.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-8149?
CVE-2017-8149 is an out-of-bounds memory access vulnerability in the boot loaders of P10 and P10 Plus Huawei mobile phones.
Which Huawei mobile phones are affected by CVE-2017-8149?
P10 and P10 Plus Huawei mobile phones with software versions before Victoria-L09AC605B162, Victoria-L29AC605B162, and Vicky-L29AC605B162 are affected by CVE-2017-8149.
What is the severity of CVE-2017-8149?
CVE-2017-8149 has a severity rating of 5.5 (high).
How can the vulnerability in CVE-2017-8149 be exploited?
The vulnerability in CVE-2017-8149 can be exploited by an attacker to trigger an out-of-bounds memory access and potentially execute arbitrary code.
Is there a fix available for CVE-2017-8149?
Yes, Huawei has released software updates to address the vulnerability in CVE-2017-8149. It is recommended to update to software versions Victoria-L09AC605B162, Victoria-L29AC605B162, or Vicky-L29AC605B162 to fix the vulnerability.