CVE-2017-8280: Buffer Overflow
Published Sep 5, 2017
·Updated
In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan calibration data store and retrieve operation, there are some potential race conditions which lead to a memory leak and a buffer overflow during the context switch.
Affected Software
2 affected components
Google Android<=8.0
Google Android
Event History
Sep 5, 2017
CVE Published
via Android·12:00 AM
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software
Sep 21, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What access and interaction does exploitation require?
The CVSS vector identifies a local attack vector, requires user interaction, and does not require privileges. Exploitation is rated high complexity.
2
Where can remediation information be checked?
The record references a Qualcomm Linux kernel msm-3.18 commit and the Android Security Bulletin dated 2017-09-01. These sources should be reviewed to determine whether the relevant fix is present in a device kernel build.