In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper validation of array index in WMA roam synchronization handler can lead to OOB write.
Vector
LOCAL
Complexity
LOW
Authentication
NONE
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE
Advisory | Patch | Confirmed | Link |
---|---|---|---|
https://www.codeaurora.org/security-bulletin/2018/09/04/... | |||
107770 | |||
https://source.codeaurora.org/quic/la/platform/vendor/qc... |