CVE-2017-8245Improper Restriction of Operations within the Bounds of a Memory Buffer in Linux

Severity
7.8HIGHNVD
EPSS
0.0%
top 87.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateMay 13

Description

In all Android releases from CAF using the Linux kernel, while processing a voice SVC request which is nonstandard by specifying a payload size that will overflow its own declared size, an out of bounds memory copy occurs.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

🔴Vulnerability Details

1
GHSA
GHSA-hf62-96cr-x335: In all Android releases from CAF using the Linux kernel, while processing a voice SVC request which is nonstandard by specifying a payload size that w2022-05-13

📋Vendor Advisories

2
Microsoft
In all Android releases from CAF using the Linux kernel while processing a voice SVC request which is nonstandard by specifying a payload size that will overflow its own declared size an out of bounds2017-05-09
Debian
CVE-2017-8245: linux - In all Android releases from CAF using the Linux kernel, while processing a voic...2017