The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can occur in wma_radio_chan_stats_event_handler() for the derived length len leading to a subsequent buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-09-17T02:11:43.560Z

Reserved: 2017-10-24T00:00:00

Link: CVE-2017-15854

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-12T20:29:00.313

Modified: 2024-11-21T03:15:20.597

Link: CVE-2017-15854

cve-icon Redhat

No data.