CVE-2017-11089 PUBLISHED

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed in nl80211_set_station when user space application sends attribute NL80211_ATTR_LOCAL_MESH_POWER_MODE with data of size less than 4 bytes

EPSS 0.64% · 70.5th percentile

Risk Scores

EPSS Score
0.64%
70.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSlinux-aws4.4.0-1017.26, 4.4.0-1018.27, 4.4.0-1020.29
Ubuntu:18.04:LTSlinux-hwe-edge5.3.0-23.25~18.04.2, 5.3.0-22.24~18.04.1, 5.3.0-19.20~18.04.2
Ubuntu:20.04:LTSlinux-gke5.4.0-1035.37, 5.4.0-1033.35, 0
Ubuntu:18.04:LTSlinux-hwe4.18.0-14.15~18.04.1, 5.3.0-76.72, 5.3.0-75.71
Ubuntu:16.04:LTSlinux-gcp4.10.0-1004.4, 0, 4.10.0-1007.7
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-89.112~14.04.1, 4.4.0-87.110~14.04.1, 4.4.0-83.106~14.04.1
Ubuntu:14.04:LTSlinux0, 3.11.0-12.19, 3.12.0-1.3
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:20.04:LTSlinux-riscv5.4.0-34.38, 5.4.0-33.37, 5.4.0-31.35
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1020.23, 4.4.0-1022.25, 4.4.0-1024.27
Ubuntu:22.04:LTSlinux-riscv5.13.0-1010.11+22.04.1, 5.15.0-1006.6, 5.15.0-1005.5
Ubuntu:16.04:LTSlinux-hwe4.8.0-52.55~16.04.1, 4.8.0-53.56~16.04.1, 4.8.0-54.57~16.04.1
Ubuntu:16.04:LTSlinux4.4.0-63.84, 4.4.0-92.115, 4.4.0-91.114
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1076.79+cvm1.1, 5.4.0-1091.96+cvm1.1, 5.4.0-1090.95+cvm1.1
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:16.04:LTSlinux-gke4.4.0-1012.12, 4.4.0-1010.10, 4.4.0-1003.3
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:16.04:LTSlinux-raspi24.4.0-1004.5, 4.4.0-1070.78, 4.4.0-1069.77
Ubuntu:20.04:LTSlinux-raspi25.4.0-1006.6, 5.4.0-1004.4, 5.3.0-1017.19

Timeline

References

Open in Interactive Console →