CVE-2017-14894 is a buffer overwrite vulnerability affecting Qualcomm Android, Firefox OS for MSM, and QRD Android devices running Linux kernel versions prior to the 2018-04-05 security patch level. The flaw occurs when the firmware provides a virtual device (vdev) ID exceeding the maximum allowed, leading to an out-of-bounds write in the wma_vdev_start_resp_handler() function. Rated with a CVSSv3 score of 7.3 (HIGH), this vulnerability is remotely exploitable with low attack complexity, requiring no user interaction or privileges. Successful exploitation could lead to partial loss of confidentiality, integrity, and availability of the affected system. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.