CVE-2017-8247: High severity Google Android vulnerability
Published Sep 5, 2017
·Updated
In all Qualcomm products with Android releases from CAF using the Linux kernel, if there is more than one thread doing the device open operation, the device may be opened more than once. This would lead to getpid being called more than once, however putpid being called only once in function "msmclose".
Affected Software
2 affected components
Google Android<=8.0
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 21, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
Does exploitation require an existing account or remote network access?
The CVSS vector indicates local access is required and no privileges are needed. It also indicates user interaction is required, so the issue is not rated as remotely exploitable over the network.
2
What is the potential impact if exploitation succeeds?
The CVSS rating assigns high impact to confidentiality, integrity, and availability. Successful exploitation could therefore expose data, alter data, or disrupt device operation.