CVE-2017-17765
Last modified
CVE-2017-17765 is a vulnerability of currently unknown severity. In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in wma_get_ll_stats_ext_buf() and are used to allocate the sizes of buffers and may be vulnerable to integer overflow leading to buffer overflow.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In all Qualcomm products with Android releases from CAF using the Linux kernel, multiple values received from firmware are not properly validated in wma_get_ll_stats_ext_buf() and are used to allocate the sizes of buffers and may be vulnerable to integer overflow leading to buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Android | All versions |
References
- http://www.securityfocus.com/bid/102974Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-02-01Vendor Advisory
- http://www.securityfocus.com/bid/102974Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-02-01Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-17765?
How severe is CVE-2017-17765?
How do I fix CVE-2017-17765?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-17759Conarc iChannel allows remote attackers to obtain sensitive …
- CVE-2017-17760OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::re…6.5
- CVE-2017-17761An issue was discovered on Ichano AtHome IP Camera devices. …
- CVE-2017-17762XML external entity (XXE) vulnerability in Episerver 7 patch…
- CVE-2017-17763SuperBeam through 4.1.3, when using the LAN or WiFi Direct S…7.5
- CVE-2017-17764In all Qualcomm products with Android releases from CAF usin…
- CVE-2017-17766In wma_peer_info_event_handler() in Android for MSM, Firefox…
- CVE-2017-17767In all Qualcomm products with Android releases from CAF usin…
- CVE-2017-17769Information leakage in Android for MSM, Firefox OS for MSM, …
- CVE-2017-17770In Qualcomm Android for MSM, Firefox OS for MSM, and QRD And…
- CVE-2017-17771In msm_isp_prepare_v4l2_buf in Android for MSM, Firefox OS f…
- CVE-2017-17772In multiple functions that process 802.11 frames, out-of-bou…9.8
Are you affected by CVE-2017-17765?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
