Userspace-controlled non null terminated parameter for IPA WAN ioctl in all Qualcomm products with Android releases from CAF using the Linux kernel can lead to exposure of kernel memory.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://source.android.com/security/bulletin/2017-07-01 | patch vendor advisory |
http://www.securityfocus.com/bid/99465 | vdb entry third party advisory |
https://source.android.com/security/bulletin/pixel/2018-04-01 |