CVE-2017-11061
Description
A buffer over-read in Android for MSM, Firefox OS for MSM, QRD Android, and CAF releases while processing the QCA_NL80211_VENDOR_SUBCMD_ROAM cfg80211 command could allow information disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A buffer over-read in Android for MSM, Firefox OS for MSM, QRD Android, and CAF releases while processing the QCA_NL80211_VENDOR_SUBCMD_ROAM cfg80211 command could allow information disclosure.
Vulnerability
A buffer over-read vulnerability exists in the Android for MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel. The issue occurs while processing the cfg80211 vendor subcommand QCA_NL80211_VENDOR_SUBCMD_ROAM. Affected versions include all Android releases from CAF up to the October 2017 security patch level [1].
Exploitation
An attacker with local access to the device or the ability to send crafted vendor commands to the wireless subsystem could trigger the buffer over-read. The attacker needs to have sufficient privileges to interact with the cfg80211 vendor command interface. The exact sequence involves sending a malicious QCA_NL80211_VENDOR_SUBCMD_ROAM command that causes the driver to read beyond the allocated buffer boundaries [1].
Impact
Successful exploitation could lead to an out-of-bounds read, potentially exposing sensitive kernel memory contents to an attacker. This could result in information disclosure, compromising the confidentiality of system data [1].
Mitigation
Google addressed this vulnerability in the October 2017 Pixel/Nexus Security Bulletin. The fix is included in the Android security patch level of 2017-10-05 or later. Users should update their devices to the latest security patch level [1].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/101160nvdThird Party AdvisoryVDB Entry
- source.android.com/security/bulletin/pixel/2017-10-01nvdVendor Advisory
News mentions
0No linked articles in our index yet.