Vulnerability Description
While parsing Netlink attributes in QCA_WLAN_VENDOR_ATTR_EXTSCAN_BSSID_HOTLIST_PARAMS_LOST_AP_SAMPLE_SIZE in qcacld 2.0 before 2017-05-16, a buffer overread could occur.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qcacld 2.0 Project | Qcacld 2.0 | < 4.5.40.004 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100210Third Party AdvisoryVDB Entry
- https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcaclPatchThird Party Advisory
- https://www.codeaurora.org/security-bulletin/2017/10/20/october-2017-v1PatchThird Party Advisory
- http://www.securityfocus.com/bid/100210Third Party AdvisoryVDB Entry
- https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcaclPatchThird Party Advisory
- https://www.codeaurora.org/security-bulletin/2017/10/20/october-2017-v1PatchThird Party Advisory
FAQ
What is CVE-2017-9694?
CVE-2017-9694 is a vulnerability with a CVSS score of 7.8 (HIGH). While parsing Netlink attributes in QCA_WLAN_VENDOR_ATTR_EXTSCAN_BSSID_HOTLIST_PARAMS_LOST_AP_SAMPLE_SIZE in qcacld 2.0 before 2017-05-16, a buffer overread could occur.
How severe is CVE-2017-9694?
CVE-2017-9694 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9694?
Check the references section above for vendor advisories and patch information. Affected products include: Qcacld 2.0 Project Qcacld 2.0.