CVE-2017-14880
CVE-2017-14880
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
03 Apr 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, while IPA WAN-driver is processing multiple requests from modem/user-space module, the global variable "num_q6_rule" does not have a mutex lock and thus can be accessed and modified by multiple threads.
Affected products
Qualcomm, Inc. · Android for MSM, Firefox OS for MSM, QRD Android