CVE-2017-11075
Description
In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, if cmd_pkt and reg_pkt are called from different userspace threads, a use after free condition can potentially occur in wdsp_glink_write().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A use-after-free in Qualcomm WCD9330 driver allows memory corruption via concurrent calls to cmd_pkt and reg_pkt from different user-space threads.
Vulnerability
In the Qualcomm WCD9330 audio codec driver used in Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch level 2018-04-05, a use-after-free condition exists in wdsp_glink_write(). The bug is triggered when cmd_pkt and reg_pkt ioctl handlers are called from different userspace threads concurrently, leading to a race condition that frees shared data while it is still in use [1].
Exploitation
An attacker requires the ability to execute two threads simultaneously on the target device, both issuing specific ioctl calls (cmd_pkt and reg_pkt) to the affected WCD9330 driver. No authentication is needed; the attacker must have local access to the device to run code that performs these concurrent calls. The race window is small and may require multiple attempts to trigger successfully [1].
Impact
Successful exploitation allows an attacker to corrupt kernel memory, potentially leading to a denial of service (device crash or reboot) or privilege escalation, as the use-after-free can be leveraged to execute arbitrary code in kernel context. The vulnerability is rated High severity (CVSS 7.8) [1].
Mitigation
The fix was included in the Android security patch level 2018-04-05. Users should ensure their devices receive the April 2018 security update or later. The Pixel/Nexus Security Bulletin April 2018 confirms this issue is addressed. No workaround is available; applying the vendor patch is necessary [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: < 2018-04-05 security patch
- Range: < 2018-04-05 security patch
- Range: < 2018-04-05 security patch
- Qualcomm, Inc./Android for MSM, Firefox OS for MSM, QRD Androidv5Range: All Android releases from CAF using the Linux kernel
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- source.android.com/security/bulletin/pixel/2018-04-01mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.