VYPR
Critical severity9.8NVD Advisory· Published Aug 18, 2017· Updated May 13, 2026

CVE-2017-7364

CVE-2017-7364

Description

In all Qualcomm products with Android releases from CAF using the Linux kernel, in function __mdss_fb_copy_destscaler_data(), variable ds_data[i].scale may still point to a user-provided address (which could point to arbitrary kernel address), so on an error condition, this user-provided address will be freed (arbitrary free), and continued operation could result in use after free condition.

Affected products

2
  • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
  • Qualcomm, Inc./All Qualcomm productsv5
    Range: All Android releases from CAF using the Linux kernel

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.