CVE-2017-8247 describes a race condition in Qualcomm products running Android with the Linux kernel, where multiple device open operations can lead to an imbalance in process ID handling, specifically multiple get_pid calls for a single put_pid call in the "msm_close" function. This vulnerability is rated as HIGH severity (CVSS 7.8), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high impacts on confidentiality, integrity, and availability. Despite its high severity, there is no known public exploit code (Metasploit, Nuclei, ExploitDB), nor is it listed in the KEV catalog, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.0CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.