CVE-2017-9693

MEDIUM

Android < 2017-06-06 - Memory Corruption

Title source: llm
STIX 2.1

Description

The length of attribute value for STA_EXT_CAPABILITY in __wlan_hdd_change_station in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-06 being less than the actual lenth of StaParams.extn_capability results in a read for extra bytes when a memcpy is done from params->ext_capab to StaParams.extn_capability using the sizeof(StaParams.extn_capability).

References (3)

Core 3

Scores

CVSS v3 5.5
EPSS 0.0019
EPSS Percentile 9.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-119
Status published
Products (1)
google/android
Published Mar 30, 2018
Tracked Since Feb 18, 2026