CVE-2017-14888
Last modified
CVE-2017-14888 is a vulnerability of currently unknown severity. In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Userspace can pass IEs to the host driver and if multiple append commands are received, then the integer variable that stores the length can overflow and the subsequent copy of the IE data may potentially lead to a heap buffer overflow.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Userspace can pass IEs to the host driver and if multiple append commands are received, then the integer variable that stores the length can overflow and the subsequent copy of the IE data may potentially lead to a heap buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
- https://source.android.com/security/bulletin/pixel/2018-11-01#qualcomm-componentsPatch, Vendor Advisory
- https://www.codeaurora.org/security-bulletin/2018/05/11/may-2018-code-aurora-security-bulletin-2Patch, Third Party Advisory
- https://source.android.com/security/bulletin/pixel/2018-11-01#qualcomm-componentsPatch, Vendor Advisory
- https://www.codeaurora.org/security-bulletin/2018/05/11/may-2018-code-aurora-security-bulletin-2Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14888?
How severe is CVE-2017-14888?
How do I fix CVE-2017-14888?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14881While calling the IPA IOCTL handler for IPA_IOC_ADD_HDR_PROC…
- CVE-2017-14882In Android for MSM, Firefox OS for MSM, QRD Android, with al…
- CVE-2017-14883In the function wma_unified_power_debug_stats_event_handler(…
- CVE-2017-14884In all Qualcomm products with Android releases from CAF usin…
- CVE-2017-14885In Android for MSM, Firefox OS for MSM, QRD Android, with al…
- CVE-2017-14887In Android for MSM, Firefox OS for MSM, QRD Android, with al…
- CVE-2017-14889In Android for MSM, Firefox OS for MSM, QRD Android, with al…
- CVE-2017-1489IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-communi…
- CVE-2017-14890In Qualcomm Android for MSM, Firefox OS for MSM, and QRD And…
- CVE-2017-14891In the KGSL driver function _gpuobj_map_useraddr() in Androi…
- CVE-2017-14892In the function msm_pcm_hw_params() in Android for MSM, Fire…
- CVE-2017-14893While flashing meta image, a buffer over-read may potentiall…
Are you affected by CVE-2017-14888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
