VYPR
High severity7.5NVD Advisory· Published Oct 10, 2017· Updated May 13, 2026

CVE-2017-11061

CVE-2017-11061

Description

A buffer over-read in Android for MSM, Firefox OS for MSM, QRD Android, and CAF releases while processing the QCA_NL80211_VENDOR_SUBCMD_ROAM cfg80211 command could allow information disclosure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer over-read in Android for MSM, Firefox OS for MSM, QRD Android, and CAF releases while processing the QCA_NL80211_VENDOR_SUBCMD_ROAM cfg80211 command could allow information disclosure.

Vulnerability

A buffer over-read vulnerability exists in the Android for MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel. The issue occurs while processing the cfg80211 vendor subcommand QCA_NL80211_VENDOR_SUBCMD_ROAM. Affected versions include all Android releases from CAF up to the October 2017 security patch level [1].

Exploitation

An attacker with local access to the device or the ability to send crafted vendor commands to the wireless subsystem could trigger the buffer over-read. The attacker needs to have sufficient privileges to interact with the cfg80211 vendor command interface. The exact sequence involves sending a malicious QCA_NL80211_VENDOR_SUBCMD_ROAM command that causes the driver to read beyond the allocated buffer boundaries [1].

Impact

Successful exploitation could lead to an out-of-bounds read, potentially exposing sensitive kernel memory contents to an attacker. This could result in information disclosure, compromising the confidentiality of system data [1].

Mitigation

Google addressed this vulnerability in the October 2017 Pixel/Nexus Security Bulletin. The fix is included in the Android security patch level of 2017-10-05 or later. Users should update their devices to the latest security patch level [1].

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.