VulnerabilityModified
CVE-2017-18155
While playing HEVC content using HD DMB in Snapdragon Automobile and Snapdragon Mobile in version MSM8996AU, SD 450, SD 625, SD 820, SD 820A, SD 835, an uninitialized variable can be used leading to a kernel fault.
HIGH 7.8EPSS 0.23%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
While playing HEVC content using HD DMB in Snapdragon Automobile and Snapdragon Mobile in version MSM8996AU, SD 450, SD 625, SD 820, SD 820A, SD 835, an uninitialized variable can be used leading to a kernel fault.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.23% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- qualcomm/msm8996au firmware · qualcomm/sd 450 firmware · qualcomm/sd 625 firmware · qualcomm/sd 820 firmware · qualcomm/sd 820a firmware · qualcomm/sd 835 firmware
- Source
- product-security@qualcomm.com
References
- https://source.android.com/security/bulletin/2018-06-01#qualcomm-componentsThird Party Advisory
- https://source.android.com/security/bulletin/2018-06-01#qualcomm-componentsThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.