CVE-2017-9696 describes a buffer over-read vulnerability in the camera driver function msm_isp_stop_stats_stream within Android for MSM, Firefox OS for MSM, and QRD Android releases utilizing the Linux kernel. This flaw arises because the num_streams variable, originating from user space, is not properly validated against the MSM_ISP_STATS_MAX limit. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity, potentially leading to high confidentiality impact without requiring user interaction. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.