CVE-2017-8251: Out-of-bounds Read
In all Qualcomm products with Android releases from CAF using the Linux kernel, in functions msmispcheckstreamcfgcmd & msmispstatsupdatecgcoverride, 'streamcfgcmd->numstreams' is not checked, and could overflow the array streamcfgcmd->streamhandle.
Affected Software
Event History
Frequently Asked Questions
Which systems are in scope for this issue?
The issue affects Qualcomm products running Android releases from CAF that use the Linux kernel. The provided data does not identify specific device models or Android version numbers.
What does an attacker need to exploit this vulnerability?
The CVSS vector indicates local access is required and user interaction is required. No privileges are required according to the vector.
What is the potential security impact?
The CVSS vector rates confidentiality, integrity, and availability impact as high. The flaw is an out-of-bounds read caused by an unchecked stream count that can overflow the stream handle array.