Uninitialized Structure Vulnerability in Qualcomm Android Products
CVE-2017-9680
7.5HIGH
Summary
This vulnerability affects all Qualcomm products utilizing Android releases from the Code Aurora Forum (CAF) that are built on the Linux kernel. It involves a security flaw where, if an invalid pointer argument is supplied from userspace, the driver may log an error message using an uninitialized structure. This situation could lead to unforeseen behaviors or security implications, as the use of uninitialized structures can potentially expose sensitive information or facilitate other exploitative actions.
Affected Version(s)
All Qualcomm products All Android releases from CAF using the Linux kernel
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved