CVE-2017-18173

HIGH

Qualcomm Snapdragon Mobile Firmware - Integer Underflow via Invalid Android Verified Boot Signature

Title source: llm
STIX 2.1

Description

In case of using an invalid android verified boot signature with very large length, an integer underflow occurs in Snapdragon Mobile in SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 810, SD 820, SD 835, SDM630, SDM636, SDM660, Snapdragon_High_Med_2016.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 26.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (13)
qualcomm/sd_425_firmware
qualcomm/sd_427_firmware
qualcomm/sd_430_firmware
qualcomm/sd_435_firmware
qualcomm/sd_450_firmware
qualcomm/sd_625_firmware
qualcomm/sd_810_firmware
qualcomm/sd_820_firmware
qualcomm/sd_835_firmware
qualcomm/sdm630_firmware
... and 3 more
Published May 06, 2019
Tracked Since Feb 18, 2026