CVE-2017-8281
published 2017-09-21CVE-2017-8281: In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event…
PriorityP418medium4.7CVSS 3.0
AVLACHPRNUIRSUCHINAN
EPSS
0.36%
28.7th percentile
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 8.0 | — | |
| android | — | — |
CVSS provenance
nvdv3.04.7MEDIUMCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fw46-jjg8-h984: In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while queryi
ghsa_unreviewed·2022-05-17
CVE-2017-8281 [MEDIUM] CWE-200 GHSA-fw46-jjg8-h984: In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while queryi
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.
Android
CVE-2017-8281: Automotive multimedia
vendor_android·2017-09-01·CVSS 4.7
CVE-2017-8281 [MEDIUM] CVE-2017-8281: Automotive multimedia
Android Security Bulletin 2017-09-01
CVE: CVE-2017-8281
Severity: MEDIUM
Type: ID
Component: Automotive multimedia
References: A-62378232
QC-CR#2015892
Red Hat
kernel: use after free in the recvmmsg exit path
vendor_redhat·2016-03-14·CVSS 9.8
CVE-2017-8281 [CRITICAL] CWE-416 kernel: use after free in the recvmmsg exit path
kernel: use after free in the recvmmsg exit path
In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.
Statement: This issue is a duplicate of CVE-2016-7117; refer to that CVE for details. It has already been fixed in all supported Red Hat products.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-8281 kernel: use after free in the recvmmsg exit path
bugzilla·2017-09-06·CVSS 9.8
CVE-2017-8281 [CRITICAL] CVE-2017-8281 kernel: use after free in the recvmmsg exit path
CVE-2017-8281 kernel: use after free in the recvmmsg exit path
Use after free vulnerability in the recvmmsg exit path was found.
Patch:
https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id%3D9be5b16de622c2426408425e3df29e945cd21d37&sa=D&usg=AFQjCNHuM63XOo5Y0C7bMJQIIedBHSDKjw
Discussion:
External References:
https://source.android.com/security/bulletin/2017-09-01
---
Statement:
This issue is a duplicate of CVE-2016-7117; refer to that CVE for details. It has already been fixed in all supported Red Hat products.
---
*** This bug has been marked as a duplicate of bug 1382268 ***
arXiv
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
arxiv_fulltext·2019-05-22
Hey Google, What Exactly Do Your Security Patches Tell Us? A Large-Scale Empirical Study on Android Patched Vulnerabilities
1.55cm
[1]
\@fnsymbol#1
Hey Google, What Exactly Do Your Security Patches Tell Us?\ Large-Scale Empirical Study on Android Patched Vulnerabilities
Sadegh Farhang Sadegh Farhang and Mehmet Bahadir Kirdan equally contributed to this work.
Pennsylvania State University
[email protected]
Mehmet Bahadir Kirdan 1
Technical University of Munich
[email protected]
Aron Laszka
University of Houston
[email protected]
Jens Grossklags
Technical University of Munich
[email protected]
## Abstract
Android has the largest market share among smartphone platforms worldwide with more than one billion active devices.
Like other platforms, security patches play a pivotal role in keeping Android devices safe from the exploitation of known vulnerabilities. Previous research efforts have documente
http://www.securityfocus.com/bid/100658https://source.android.com/security/bulletin/2017-09-01https://source.android.com/security/bulletin/pixel/2017-12-01http://www.securityfocus.com/bid/100658https://source.android.com/security/bulletin/2017-09-01https://source.android.com/security/bulletin/pixel/2017-12-01
2017-09-21
Published