CVE-2017-14891: Google Android

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

In the KGSL driver function _gpuobj_map_useraddr() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-12, the contents of the stack can get leaked due to an uninitialized variable.

Affected products

  • Google Android: affected versions not specified

Published 2018-03-30. Last modified 2026-06-17.