CVE-2017-18050
Description
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev_map in wma_tbttoffset_update_event_handler(), which is received from firmware, leads to potential buffer overwrite and out of bounds memory read.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper input validation in WLAN driver's wma_tbttoffset_update_event_handler allows buffer overwrite and OOB read via crafted firmware event.
Vulnerability
An improper input validation vulnerability exists in the WLAN driver of Android for MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel. The flaw resides in the wma_tbttoffset_update_event_handler() function, which processes a vdev_map field received from firmware. Insufficient validation of this field can lead to a buffer overwrite and out-of-bounds memory read. Affected versions include all Android releases from CAF using the Linux kernel, as referenced in the March 2018 Pixel/Nexus Security Bulletin [1].
Exploitation
An attacker with the ability to control or inject firmware messages (e.g., via a compromised baseband or malicious firmware) can send a crafted wma_tbttoffset_update_event containing an invalid vdev_map value. No additional authentication or user interaction is required beyond the ability to deliver the event to the WLAN driver. The handler fails to properly validate the size or bounds of vdev_map, leading to the memory corruption.
Impact
Successful exploitation results in a buffer overwrite and out-of-bounds memory read within the kernel context. This could allow an attacker to corrupt kernel memory, potentially leading to arbitrary code execution or sensitive information disclosure. The impact is at the kernel privilege level, compromising the confidentiality, integrity, and availability of the system.
Mitigation
Google addressed this vulnerability in the March 2018 Pixel/Nexus Security Bulletin with a security patch level of 2018-03-05 or later [1]. Devices that have installed this patch level are no longer vulnerable. For other Android devices using CAF kernels, OEMs must incorporate the fix from the CAF source tree. No workaround is available; updating to the patched version is the only mitigation.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- source.android.com/security/bulletin/pixel/2018-03-01mitrex_refsource_CONFIRM
- source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.