CVE-2017-11063: Google Android

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, as a result of a race condition between two userspace processes that interact with the driver concurrently, a null pointer dereference can potentially occur.

Affected products

  • Google Android: version 8.0 only

Published 2017-10-10. Last modified 2026-06-17.