Vulnerability Description
In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Msm8996Au Firmware | - |
| Qualcomm | Msm8996Au | - |
| Qualcomm | Sd425 Firmware | - |
| Qualcomm | Sd425 | - |
| Qualcomm | Sd427 Firmware | - |
| Qualcomm | Sd427 | - |
| Qualcomm | Sd430 Firmware | - |
| Qualcomm | Sd430 | - |
| Qualcomm | Sd435 Firmware | - |
| Qualcomm | Sd435 | - |
| Qualcomm | Sd450 Firmware | - |
| Qualcomm | Sd450 | - |
| Qualcomm | Sd625 Firmware | - |
| Qualcomm | Sd625 | - |
| Qualcomm | Sd650 Firmware | - |
| Qualcomm | Sd650 | - |
| Qualcomm | Sd652 Firmware | - |
| Qualcomm | Sd652 | - |
| Qualcomm | Sd820 Firmware | - |
| Qualcomm | Sd820 | - |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1041432Third Party AdvisoryVDB Entry
- https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-cVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
- http://www.securitytracker.com/id/1041432Third Party AdvisoryVDB Entry
- https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-cVendor Advisory
- https://www.qualcomm.com/company/product-security/bulletinsVendor Advisory
FAQ
What is CVE-2017-18302?
CVE-2017-18302 is a vulnerability with a CVSS score of 4.7 (MEDIUM). In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Sna...
How severe is CVE-2017-18302?
CVE-2017-18302 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-18302?
Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Msm8996Au Firmware, Qualcomm Msm8996Au, Qualcomm Sd425 Firmware, Qualcomm Sd425, Qualcomm Sd427 Firmware.