Vulnerability Description
While playing HEVC content using HD DMB in Snapdragon Automobile and Snapdragon Mobile in version MSM8996AU, SD 450, SD 625, SD 820, SD 820A, SD 835, an uninitialized variable can be used leading to a kernel fault.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Msm8996Au Firmware | - |
| Qualcomm | Msm8996Au | - |
| Qualcomm | Sd 450 Firmware | - |
| Qualcomm | Sd 450 | - |
| Qualcomm | Sd 625 Firmware | - |
| Qualcomm | Sd 625 | - |
| Qualcomm | Sd 820 Firmware | - |
| Qualcomm | Sd 820 | - |
| Qualcomm | Sd 820A Firmware | - |
| Qualcomm | Sd 820A | - |
| Qualcomm | Sd 835 Firmware | - |
| Qualcomm | Sd 835 | - |
Related Weaknesses (CWE)
References
- https://source.android.com/security/bulletin/2018-06-01#qualcomm-componentsThird Party Advisory
- https://source.android.com/security/bulletin/2018-06-01#qualcomm-componentsThird Party Advisory
FAQ
What is CVE-2017-18155?
CVE-2017-18155 is a vulnerability with a CVSS score of 7.8 (HIGH). While playing HEVC content using HD DMB in Snapdragon Automobile and Snapdragon Mobile in version MSM8996AU, SD 450, SD 625, SD 820, SD 820A, SD 835, an uninitialized variable can be used leading to a...
How severe is CVE-2017-18155?
CVE-2017-18155 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18155?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Msm8996Au Firmware, Qualcomm Msm8996Au, Qualcomm Sd 450 Firmware, Qualcomm Sd 450, Qualcomm Sd 625 Firmware.