CVE-2017-11076

CRITICAL

Hardware Revision - Memory Corruption

Title source: llm
STIX 2.1

Description

On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.

Scores

CVSS v3 9.8
EPSS 0.0028
EPSS Percentile 51.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-823
Status published
Products (27)
qualcomm/msm8909w_firmware
qualcomm/msm8996au_firmware
qualcomm/sd_205_firmware
qualcomm/sd_210_firmware
qualcomm/sd_212_firmware
qualcomm/sd_415_firmware
qualcomm/sd_425_firmware
qualcomm/sd_427_firmware
qualcomm/sd_430_firmware
qualcomm/sd_435_firmware
... and 17 more
Published Nov 26, 2024
Tracked Since Feb 18, 2026