CVE-2017-18057

HIGH

Google Android - Improper Input Validation

Title source: rule
STIX 2.1

Description

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev id in wma_nlo_scan_cmp_evt_handler(), which is received from firmware, leads to potential out of bounds memory read.

Scores

CVSS v3 7.5
EPSS 0.0012
EPSS Percentile 30.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-125 CWE-20
Status published
Products (1)
google/android
Published Mar 16, 2018
Tracked Since Feb 18, 2026