CVE-2017-9725
published 2017-09-21CVE-2017-9725: In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets…
PriorityP433high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.23%
66.0th percentile
In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.3.1-1 (bookworm) | linux 4.3.1-1 (bookworm) |
| android | <= 8.0 | — | |
| android | — | — | |
| linux | linux_kernel | >= 0 < 4.3.1-1 | 4.3.1-1 |
| linux | linux_kernel | >= 0 < 4.3.1-1 | 4.3.1-1 |
| linux | linux_kernel | >= 0 < 4.3.1-1 | 4.3.1-1 |
| linux | linux_kernel | >= 0 < 4.3.1-1 | 4.3.1-1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2017-9725: Memory subsystem
vendor_android·2017-09-01·CVSS 7.8
CVE-2017-9725 [HIGH] CVE-2017-9725: Memory subsystem
Android Security Bulletin 2017-09-01
CVE: CVE-2017-9725
Severity: HIGH
Type: EoP
Component: Memory subsystem
References: A-38195738
QC-CR#896659
Debian
CVE-2017-9725: linux - In all Qualcomm products with Android releases from CAF using the Linux kernel, ...
vendor_debian·2017·CVSS 7.8
CVE-2017-9725 [HIGH] CVE-2017-9725: linux - In all Qualcomm products with Android releases from CAF using the Linux kernel, ...
In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail.
Scope: local
bookworm: resolved (fixed in 4.3.1-1)
bullseye: resolved (fixed in 4.3.1-1)
forky: resolved (fixed in 4.3.1-1)
sid: resolved (fixed in 4.3.1-1)
trixie: resolved (fixed in 4.3.1-1)
Red Hat
kernel: Incorrect type conversion for size during dma allocation
vendor_redhat·2015-10-12·CVSS 7.8
CVE-2017-9725 [HIGH] CWE-681 kernel: Incorrect type conversion for size during dma allocation
kernel: Incorrect type conversion for size during dma allocation
In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail.
A flaw was found where the kernel truncated the value used to indicate the size of a buffer which it would later become zero using an untruncated value. This can corrupt memory outside of the original allocation.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2.
Future Linux kernel updates for the respective releases may address this issue.
Package
GHSA
GHSA-m96m-qc9m-gfxj: In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size
ghsa_unreviewed·2022-05-13
CVE-2017-9725 [HIGH] CWE-682 GHSA-m96m-qc9m-gfxj: In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size
In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail.
OSV
CVE-2017-9725: In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size
osv·2017-09-21·CVSS 7.8
CVE-2017-9725 [HIGH] CVE-2017-9725: In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size
In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-9725 kernel: Incorrect type conversion for size during dma allocation
bugzilla·2017-09-06·CVSS 7.8
CVE-2017-9725 [HIGH] CVE-2017-9725 kernel: Incorrect type conversion for size during dma allocation
CVE-2017-9725 kernel: Incorrect type conversion for size during dma allocation
A flaw was found in the Linux kernels implementation of DMA memory allocation.
When allocating a DMA buffer, a section of memory is allocated and then set to zeros. The size parameter of allocation was truncated due to an incorrect casting when the allocation function is called. During clearing the allocation used an untruncated value as the size to clear and would "zero" a larger section of kernel memory than was allocated, possibly corrupting memory and allowing for privilege escalation.
At this time Red Hat Product Security believes that there is no direct control of the size parameter used in this function in Red Hat kernels.
Patch:
https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?h=aosp/and
Bugzilla
CVE-2017-9725 kernel: Incorrect type conversion for size during dma allocation [fedora-all]
bugzilla·2017-09-06·CVSS 7.8
CVE-2017-9725 [HIGH] CVE-2017-9725 kernel: Incorrect type conversion for size during dma allocation [fedora-all]
CVE-2017-9725 kernel: Incorrect type conversion for size during dma allocation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
http://www.securityfocus.com/bid/100658https://access.redhat.com/errata/RHSA-2018:0676https://access.redhat.com/errata/RHSA-2018:1062https://access.redhat.com/errata/RHSA-2018:1130https://access.redhat.com/errata/RHSA-2018:1170https://source.android.com/security/bulletin/2017-09-01http://www.securityfocus.com/bid/100658https://access.redhat.com/errata/RHSA-2018:0676https://access.redhat.com/errata/RHSA-2018:1062https://access.redhat.com/errata/RHSA-2018:1130https://access.redhat.com/errata/RHSA-2018:1170https://source.android.com/security/bulletin/2017-09-01
2017-09-21
Published