CVE-2017-14883: Google Android

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

In the function wma_unified_power_debug_stats_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-18, if the value param_buf->num_debug_register received from the FW command buffer is close to max of uint32, then the computation performed using this variable to calculate stats_registers_len may overflow to a smaller value leading to less than required memory allocated for power_stats_results and potentially a buffer overflow while copying the FW buffer to local buffer.

Affected products

  • Google Android: affected versions not specified

Published 2018-03-30. Last modified 2026-06-17.