In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition can allow access to already freed memory while querying event status via DCI.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://source.android.com/security/bulletin/2017-09-01 | patch vendor advisory |
https://source.android.com/security/bulletin/pixel/2017-12-01 | |
http://www.securityfocus.com/bid/100658 | vdb entry third party advisory |