Android Patchday: 57 holes closed

  • 7 February 2018
  • 1 reply
  • 336 views

Userlevel 7
Badge +52
The complete changelog is available here, every Android version beginning from Android 5.1.1 are supported. 28 patches overall which including 57 holes in total.

Media Framework

CVEReferencesTypeSeverityUpdated AOSP versions
CVE-2017-13228A-69478425RCECritical6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1
CVE-2017-13231A-67962232EoPHigh8.0, 8.1
CVE-2017-13232A-68953950IDHigh5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1
CVE-2017-13230A-65483665DoSHigh7.0, 7.1.1, 7.1.2, 8.0, 8.1
RCECritical5.1.1, 6.0, 6.0.1
CVE-2017-13233A-62851602DoSHigh5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1
CVE-2017-13234A-68159767DoSHigh5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1

System

CVEReferencesTypeSeverityUpdated AOSP versions
CVE-2017-13236A-68217699EoPModerate8.0, 8.1

HTC components

CVEReferencesTypeSeverityComponent
CVE-2017-13238A-64610940*IDHighBootloader
CVE-2017-13247A-71486645*EoPModerateBootloader

Kernel components

CVEReferencesTypeSeverityComponent
CVE-2017-15265A-67900971
Upstream kernelEoPHighALSA
CVE-2015-9016A-63083046
Upstream kernelEoPHighMulti-queue block IO
CVE-2017-17770A-65853158*EoPHighKernel

NVIDIA components

CVEReferencesTypeSeverityComponent
CVE-2017-6279A-65023166*
N-CVE-2017-6279EoPHighMedia framework
CVE-2017-6258A-38027496*
N-CVE-2017-6258EoPHighMedia framework

Qualcomm components

CVEReferencesTypeSeverityComponent
CVE-2017-15817A-68992394
QC-CR#2076603 [2] [ 2]RCECriticalWLan
CVE-2017-17760A-68992416
QC-CR#2082544 [2] [ 2]RCECriticalWLan
CVE-2017-11041A-35269676*
QC-CR#2053101EoPHighMedia framework
CVE-2017-17767A-64750179*
QC-CR#2115779EoPHighMedia framework
CVE-2017-17765A-68992445
QC-CR#2115112EoPHighWLan
CVE-2017-17762A-68992439
QC-CR#2114426EoPHighWLan
CVE-2017-14884A-68992429
QC-CR#2113052EoPHighWLan
CVE-2017-15829A-68992397
QC-CR#2097917EoPHighGraphics_Linux
CVE-2017-15820A-68992396
QC-CR#2093377EoPHighGraphics_Linux
CVE-2017-17764A-68992443
QC-CR#2114789EoPHighWLan
CVE-2017-17761A-68992434
QC-CR#2114187EoPHighWLan

Qualcomm closed-source components

CVEReferencesTypeSeverityComponent
CVE-2017-14910A-62212114*N/AHighClosed-source component
 
via chefkochblog.wordpress.com
 

1 reply

Userlevel 7
Badge +54
Thank you Petr.

Reply