Security Advisory

CVE-2017-9696

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-11-16 22:00:00
Last updated 2024-09-16 19:47:18
Assigner qualcomm
CVSS score not scored
State PUBLISHED

Description

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, buffer over-read is possible in camera driver function msm_isp_stop_stats_stream. Variable stream_cfg_cmd->num_streams is from userspace, and it is not checked against "MSM_ISP_STATS_MAX".