CVE-2017-15814 describes an out-of-bounds read vulnerability in the msm_flash_subdev_do_ioctl function within the Linux kernel code used by Android for MSM, Firefox OS for MSM, and QRD Android. This flaw, caused by improper input validation when flash_data.cfg_type is CFG_FLASH_INIT, could lead to local information disclosure. With a CVSS score of 4.4 (Medium), exploitation requires System execution privileges and local access, but no user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.