Out of bounds read when processing a voice SVC request (CVE-2017-8245)
Release Date:
May 1, 2017
Affected Projects:
Android for MSMFirefox OS for MSMQRD Android
Advisory ID:
QCIR-2017-00036-1
CVE ID(s):
Summary:
The following security vulnerabilities have been identified: CVE-2017-8245 While processing a voice SVC request which is nonstandard by specifying a payload size that will overflow its own declared size, an out of bounds memory copy occurs.
Access Vector: Local
Security Risk: Medium
Access Vector: Local
Affected Versions:
All Android releases from CAF using the Linux kernel
Patch:
We advise customers to apply the following patches:
Individual Patches
CVE-2017-8245:
- https://source.codeaurora.org/quic/la//kernel/msm-3.10/commit/?id=ececf97911515114030bef1fc6df630dbb706f17
- https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=f53af3805879292423465cd0877cc7a75131ce10
- https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=5b2f6e011ba92f28e8d7dbeb11c4ee7344c33186
Acknowledgement:
Qualcomm Innovation Center, Inc. (QuIC) thanks Yonggang Guo (@guoygang) of IceSword Lab, Qihoo 360 Technology Co. Ltd for bringing this issue to QuIC’s attention.
Revisions:
Initial revision
Contact:
security-advisory@quicinc.com