CVE-2017-9725 PUBLISHED

In all Qualcomm products with Android releases from CAF using the Linux kernel, during DMA allocation, due to wrong data type of size, allocation size gets truncated which makes allocation succeed when it should fail.

EPSS 0.18% · 40.0th percentile

Risk Scores

EPSS Score
0.18%
40.0th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-azure-edge0, 5.0.0-1012.12~18.04.2, 4.18.0-1008.8~18.04.1
Ubuntu:22.04:LTSlinux-riscv5.15.0-1020.23, 5.15.0-1019.22, 5.15.0-1018.21
Ubuntu:18.04:LTSlinux-aws-5.00, 5.0.0-1027.30, 5.0.0-1025.28
Ubuntu:18.04:LTSlinux-gcp4.15.0-1037.39, 0, 4.15.0-1001.1
Ubuntu:18.04:LTSlinux-gcp-edge4.18.0-1006.7~18.04.1, 4.18.0-1007.8~18.04.1, 4.18.0-1008.9~18.04.1
Ubuntu:16.04:LTSlinux-hwe-edge4.10.0-20.22~16.04.1, 4.10.0-19.21~16.04.1, 4.10.0-14.16~16.04.1
Ubuntu:18.04:LTSlinux-azure4.18.0-1018.18~18.04.1, 4.18.0-1019.19~18.04.1, 4.18.0-1020.20~18.04.1
Ubuntu:Pro:14.04:LTSlinux3.13.0-181.232, 3.13.0-182.233, 3.13.0-183.234
Ubuntu:18.04:LTSlinux-oracle-5.00, 5.0.0-1014.19, 5.0.0-1013.18
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1078.81+cvm1.1, 5.4.0-1080.83+cvm1.1, 5.4.0-1083.87+cvm1.1
Ubuntu:20.04:LTSlinux-raspi20, 5.4.0-1006.6, 5.4.0-1004.4
Ubuntu:16.04:LTSlinux-raspi24.4.0-1016.22, 4.4.0-1010.13, 4.4.0-1012.16
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:20.04:LTSlinux-gke5.4.0-1081.87, 5.4.0-1083.89, 5.4.0-1084.90
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:20.04:LTSlinux-gkeop-5.155.15.0-1032.38~20.04.1, 0, 5.15.0-1003.5~20.04.2
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:20.04:LTSlinux-gkeop5.4.0-1010.11, 5.4.0-1009.10, 5.4.0-1008.9

Timeline

References

Open in Interactive Console →