Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f2c2-hw9j-p96c

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled variables "nr_cmds" and "nr_bos" number are passed across functions without any check. An integer overflow to buffer overflow (with a smaller buffer allocated) may occur when they are too large or negative.

In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled variables "nr_cmds" and "nr_bos" number are passed across functions without any check. An integer overflow to buffer overflow (with a smaller buffer allocated) may occur when they are too large or negative.

EPSS

Процентиль: 18%
0.00057
Низкий

7.8 High

CVSS3

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7.8
nvd
больше 8 лет назад

In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled variables "nr_cmds" and "nr_bos" number are passed across functions without any check. An integer overflow to buffer overflow (with a smaller buffer allocated) may occur when they are too large or negative.

EPSS

Процентиль: 18%
0.00057
Низкий

7.8 High

CVSS3

Дефекты

CWE-190