← back
CVE-2017-18070

CVE-2017-18070

EPSS 0.2%
In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of variable "event->num_ndp_end_rsp_per_ndi_list" is very large which can then lead to a heap overwrite of the heap object end_rsp in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →