Description
While parsing Netlink attributes in QCA_WLAN_VENDOR_ATTR_EXTSCAN_BSSID_HOTLIST_PARAMS_LOST_AP_SAMPLE_SIZE in qcacld 2.0 before 2017-05-16, a buffer overread could occur.
References (3)
Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://www.codeaurora.org/security-bulletin/2017/10/20/october-2017-v1
Patch, Third Party Advisory x_refsource_misc
https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=1e47d44de7bab5500d27f17ae5c4ebebc7d2b4ef
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/100210
Scores
CVSS v3
7.8
EPSS
0.0042
EPSS Percentile
33.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
Status
published
Products (1)
qcacld_2.0_project/qcacld_2.0
< 4.5.40.004
Published
Mar 30, 2018
Tracked Since
Feb 18, 2026