Uninitialized Structure Vulnerability in Qualcomm Android Products
CVE-2017-9680

7.5HIGH

Key Information:

Vendor
Qualcomm
Vendor
CVE Published:
18 August 2017

Summary

This vulnerability affects all Qualcomm products utilizing Android releases from the Code Aurora Forum (CAF) that are built on the Linux kernel. It involves a security flaw where, if an invalid pointer argument is supplied from userspace, the driver may log an error message using an uninitialized structure. This situation could lead to unforeseen behaviors or security implications, as the use of uninitialized structures can potentially expose sensitive information or facilitate other exploitative actions.

Affected Version(s)

All Qualcomm products All Android releases from CAF using the Linux kernel

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.