CVE Database
/

CVE-2017-7364

Back to search

CVE-2017-7364

Published: Aug 18, 2017

Modified: Sep 17, 2024

PUBLISHED

Description

In all Qualcomm products with Android releases from CAF using the Linux kernel, in function __mdss_fb_copy_destscaler_data(), variable ds_data[i].scale may still point to a user-provided address (which could point to arbitrary kernel address), so on an error condition, this user-provided address will be freed (arbitrary free), and continued operation could result in use after free condition.

VendorProductVersions

Qualcomm, Inc.

All Qualcomm products

affected
All Android releases from CAF using the Linux kernel

References

1038623
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now