CVE-2017-11056: Google Android

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while doing sha and cipher operations, a userspace buffer is directly accessed in kernel space potentially leading to a page fault.

Affected products

  • Google Android: version 8.0 only

Published 2017-10-10. Last modified 2026-06-17.