VulnerabilityModified
CVE-2017-9691
There is a race condition in Android for MSM, Firefox OS for MSM, and QRD Android that allows to access to already free'd memory in the debug message output functionality contained within the mobicore driver.
MEDIUM 4.7EPSS 0.12%
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
There is a race condition in Android for MSM, Firefox OS for MSM, and QRD Android that allows to access to already free'd memory in the debug message output functionality contained within the mobicore driver.
- CVSS 3.0
- 4.7 MEDIUMCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- google/android
- Source
- product-security@qualcomm.com
References
- http://www.securityfocus.com/bid/100213Third Party Advisory, VDB Entry
- https://www.codeaurora.org/security-bulletin/2017/11/28/november-2017-security-bulletinPatch, Third Party Advisory
- http://www.securityfocus.com/bid/100213Third Party Advisory, VDB Entry
- https://www.codeaurora.org/security-bulletin/2017/11/28/november-2017-security-bulletinPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.