In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions.

Project Subscriptions

Vendors Products
Qualcomm Subscribe
Msm8996au Subscribe
Msm8996au Firmware Subscribe
Sd425 Firmware Subscribe
Sd427 Firmware Subscribe
Sd430 Firmware Subscribe
Sd435 Firmware Subscribe
Sd450 Firmware Subscribe
Sd625 Firmware Subscribe
Sd650 Firmware Subscribe
Sd652 Firmware Subscribe
Sd820 Firmware Subscribe
Sd820a Firmware Subscribe
Sd835 Firmware Subscribe
Sda660 Firmware Subscribe
Sdm429 Firmware Subscribe
Sdm439 Firmware Subscribe
Sdm630 Firmware Subscribe
Sdm632 Firmware Subscribe
Sdm636 Firmware Subscribe
Sdm660 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2017-9428 In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-08-05T21:20:51.029Z

Reserved: 2018-06-15T00:00:00.000Z

Link: CVE-2017-18302

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-20T13:29:00.510

Modified: 2024-11-21T03:19:48.723

Link: CVE-2017-18302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses