Vulnerability Name: | CVE-2017-9725 (CCN-132422) | ||||||||||||||||||
Assigned: | 2015-10-12 | ||||||||||||||||||
Published: | 2015-10-12 | ||||||||||||||||||
Updated: | 2019-10-03 | ||||||||||||||||||
Summary: | In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail. | ||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.8 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||
Vulnerability Type: | CWE-682 CWE-681 | ||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-9725 Source: CCN Type: IBM Security Bulletin 715699 (QRadar Network Security) IBM QRadar Network Security is affected by Linux kernel vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry 100658 Source: CCN Type: BID-100658 Google Android Qualcomm Components Multiple Security Vulnerabilities Source: REDHAT Type: UNKNOWN RHSA-2018:0676 Source: REDHAT Type: UNKNOWN RHSA-2018:1062 Source: REDHAT Type: UNKNOWN RHSA-2018:1130 Source: REDHAT Type: UNKNOWN RHSA-2018:1170 Source: CCN Type: Google Web site Android Source: XF Type: UNKNOWN android-cve20179725-sec-bypass(132422) Source: CCN Type: Android Open Source Project Android Security Bulletin—September 2017 Source: CONFIRM Type: Patch, Vendor Advisory https://source.android.com/security/bulletin/2017-09-01 Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-9725 | ||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration CCN 1: ![]() | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |