CVE-2017-18302 Details
Description
In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components | CVE | Vendor Advisory |
| https://www.qualcomm.com/company/product-security/bulletins | CVE | Vendor Advisory |
| http://www.securitytracker.com/id/1041432 | CVE | Third Party AdvisoryVDB Entry |
| https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components | [email protected] | Vendor Advisory |
| https://www.qualcomm.com/company/product-security/bulletins | [email protected] | Vendor Advisory |
| http://www.securitytracker.com/id/1041432 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qualcomm msm8996au firmware | All versions |
CPE
Remediation
| |
| qualcomm msm8996au | All versions |
CPE
Remediation
| |
| qualcomm sd425 firmware | All versions |
CPE
Remediation
| |
| qualcomm sd425 | All versions |
CPE
Remediation
| |
| qualcomm sd427 firmware | All versions |
CPE
Remediation
| |
| qualcomm sd427 | All versions |
CPE
Remediation
| |
| qualcomm sd430 firmware | All versions |
CPE
Remediation
| |
| qualcomm sd430 | All versions |
CPE
Remediation
| |
| qualcomm sd435 firmware | All versions |
CPE
Remediation
| |
| qualcomm sd435 | All versions |
CPE
Remediation
| |
| qualcomm sd450 firmware | All versions |
CPE
Remediation
| |
| qualcomm sd450 | All versions |
CPE
Remediation
| |
| qualcomm sd625 firmware | All versions |
CPE
Remediation
| |
| qualcomm sd625 | All versions |
CPE
Remediation
| |
| qualcomm sd650 firmware | All versions |
CPE
Remediation
| |
| qualcomm sd650 | All versions |
CPE
Remediation
| |
| qualcomm sd652 firmware | All versions |
CPE
Remediation
| |
| qualcomm sd652 | All versions |
CPE
Remediation
| |
| qualcomm sd820 firmware | All versions |
CPE
Remediation
| |
| qualcomm sd820 | All versions |
CPE
Remediation
| |
| qualcomm sd820a firmware | All versions |
CPE
Remediation
| |
| qualcomm sd820a | All versions |
CPE
Remediation
| |
| qualcomm sd835 firmware | All versions |
CPE
Remediation
| |
| qualcomm sd835 | All versions |
CPE
Remediation
| |
| qualcomm sda660 firmware | All versions |
CPE
Remediation
| |
| qualcomm sda660 | All versions |
CPE
Remediation
| |
| qualcomm sdm429 firmware | All versions |
CPE
Remediation
| |
| qualcomm sdm429 | All versions |
CPE
Remediation
| |
| qualcomm sdm439 firmware | All versions |
CPE
Remediation
| |
| qualcomm sdm439 | All versions |
CPE
Remediation
| |
| qualcomm sdm630 firmware | All versions |
CPE
Remediation
| |
| qualcomm sdm630 | All versions |
CPE
Remediation
| |
| qualcomm sdm632 firmware | All versions |
CPE
Remediation
| |
| qualcomm sdm632 | All versions |
CPE
Remediation
| |
| qualcomm sdm636 firmware | All versions |
CPE
Remediation
| |
| qualcomm sdm636 | All versions |
CPE
Remediation
| |
| qualcomm sdm660 firmware | All versions |
CPE
Remediation
| |
| qualcomm sdm660 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 23, 2018 | Initial Analysis | [email protected] |
| Sep 21, 2018 | CVE Modified | [email protected] |