In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, buffer over-read is possible in camera driver function msm_isp_stop_stats_stream. Variable stream_cfg_cmd->num_streams is from userspace, and it is not checked against "MSM_ISP_STATS_MAX".
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published: 2017-11-16T22:00:00Z

Updated: 2024-09-16T19:47:18.481Z

Reserved: 2017-06-15T00:00:00

Link: CVE-2017-9696

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-11-16T22:29:01.550

Modified: 2019-10-03T00:03:26.223

Link: CVE-2017-9696

cve-icon Redhat

No data.