CVE-2017-18054 describes a buffer overflow vulnerability in Android for MSM, Firefox OS for MSM, and QRD Android, specifically within the Linux kernel components from CAF. This flaw arises from improper input validation of 'num_vdev_mac_entries' received from firmware, affecting Google Android devices. Rated 7.8 HIGH, the vulnerability allows a local attacker with low privileges to achieve high confidentiality, integrity, and availability impacts. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in the KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.