1 <html devsite><head> 2 <title>Android - 2017 5 </title> 3 <meta name="project_path" value="/_project.yaml"/> 4 <meta name="book_path" value="/_book.yaml"/> 5 </head> 6 <body> 7 <!-- 8 Copyright 2017 The Android Open Source Project 9 10 Licensed under the Apache License, Version 2.0 (the "License"); 11 you may not use this file except in compliance with the License. 12 You may obtain a copy of the License at 13 14 http://www.apache.org/licenses/LICENSE-2.0 15 16 Unless required by applicable law or agreed to in writing, software 17 distributed under the License is distributed on an "AS IS" BASIS, 18 WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. 19 See the License for the specific language governing permissions and 20 limitations under the License. 21 --> 22 23 <p><em>2017 5 1 | 2017 5 2 </em></p> 24 25 <p>Android Android Nexus OTAGoogle <a href="https://developers.google.com/android/nexus/images">Google </a>2017 5 5 <a href="https://support.google.com/pixelphone/answer/4457705#pixel_phones&nexus_devices">Pixel Nexus </a></p> 26 27 <p> 2017 4 3 Android AOSPAOSP </p> 28 29 <p>MMS <a href="/security/overview/updates-resources.html#severity"></a></p> 30 31 <p><a href="/security/enhancements/index.html">Android </a> <a href="https://developer.android.com/training/safetynet/index.html">SafetyNet</a> <a href="#mitigations">Android Google </a>Android </p> 32 33 <p></p> 34 <h2 id="announcements"></h2> 35 <ul> 36 <li>2 Android Android <a href="#common-questions-and-answers"></a> 37 <ul> 38 <li><strong>2017-05-01</strong>: 2017-05-01 </li> 39 <li><strong>2017-05-05</strong>: 2017-05-01 2017-05-05 </li> 40 </ul> 41 </li> 42 <li> Google 2017 5 5 1 OTA </li> 43 </ul> 44 45 <h2 id="mitigations">Android Google </h2> 46 47 <p><a href="/security/enhancements/index.html">Android </a> SafetyNet Android </p> 48 49 <ul> 50 <li>Android Android Google Android </li> 51 <li>Android <a href="/security/reports/Google_Android_Security_2016_Report_Final.pdf"> SafetyNet</a> <a href="/security/reports/Google_Android_Security_PHA_classifications.pdf"></a><a href="http://www.android.com/gms">Google </a>Google Play Google Play </li> 52 <li>Google </li> 53 </ul> 54 55 <h2 id="acknowledgements"></h2> 56 57 <p></p> 58 <ul> 59 <li>ADlab of Venustech: CVE-2017-0630</li> 60 <li>Tencent KeenLab<a href="https://twitter.com/keen_lab">@keen_lab</a> Di Shen<a href="https://twitter.com/returnsme">@returnsme</a>: CVE-2016-10287</li> 61 <li>Trend Micro Ecular Xu: CVE-2017-0599CVE-2017-0635</li> 62 <li><a href="http://www.ms509.com">MS509Team</a> En He<a href="https://twitter.com/heeeeen4x">@heeeeen4x</a>Bo Liu: CVE-2017-0601</li> 63 <li><a href="https://twrp.me/">Team Win Recovery Project</a> Ethan Yonker: CVE-2017-0493</li> 64 <li>Qihoo 360 Technology Co. Ltd. IceSword Lab Gengjia Chen<a href="https://twitter.com/chengjia4574">@chengjia4574</a><a href="http://weibo.com/jfpan">pjf</a>: CVE-2016-10285CVE-2016-10288CVE-2016-10290CVE-2017-0624CVE-2017-0616CVE-2017-0617CVE-2016-10294CVE-2016-10295CVE-2016-10296</li> 65 <li>Tencent PC Manager godzheng <a href="https://twitter.com/virtualseekers">@VirtualSeekers</a>: CVE-2017-0602</li> 66 <li><a href="http://tuncay2.web.engr.illinois.edu"> </a> <a href="https://www.linkedin.com/in/g%C3%BCliz-seray-tuncay-952a1b9/">Gliz Seray Tuncay</a>: CVE-2017-0593</li> 67 <li>Qihoo 360 Technology Co. Ltd. Alpha Team Hao ChenGuang Gong: CVE-2016-10283</li> 68 <li>Xiaomi Inc. Juhu NieYang ChengNan LiQiwu Huang: CVE-2016-10276</li> 69 <li><a href="https://github.com/michalbednarski">Micha Bednarski</a>: CVE-2017-0598</li> 70 <li>TeslaProduct Security Team Nathan Crandall<a href="https://twitter.com/natecray">@natecray</a>: CVE-2017-0331CVE-2017-0606</li> 71 <li><a href="mailto:jiych.guru (a] gmail.com">Niky1235</a><a href="https://twitter.com/jiych_guru">@jiych_guru</a>: CVE-2017-0603</li> 72 <li>Alibaba Mobile Security Group Peng XiaoChengming YangNing YouChao YangYang song: CVE-2016-10281CVE-2016-10280</li> 73 <li><a href="https://alephsecurity.com/">Aleph Research</a> Roee Hay<a href="https://twitter.com/roeehay">@roeehay</a>: CVE-2016-10277</li> 74 <li><a href="mailto:sbauer (a] plzdonthack.me">Scott Bauer</a><a href="https://twitter.com/ScottyBauer1">@ScottyBauer1</a>: CVE-2016-10274</li> 75 <li><a href="http://c0reteam.org">C0RE Team</a> <a href="mailto:segfault5514 (a] gmail.com">Tong Lin</a><a href="mailto:computernik (a] gmail.com">Yuan-Tsung Lo</a>Xuxian Jiang: CVE-2016-10291</li> 76 <li>Vasily Vasiliev: CVE-2017-0589</li> 77 <li><a href="http://www.trendmicro.com">Trend Micro</a><a href="http://blog.trendmicro.com/trendlabs-security-intelligence/category/mobile">Mobile Threat Response Team</a> V.E.O<a href="https://twitter.com/vysea">@VYSEa</a>: CVE-2017-0590CVE-2017-0587CVE-2017-0600</li> 78 <li>Tencent Security Platform Department Xiling Gong: CVE-2017-0597</li> 79 <li>360 Marvel Team Xingyuan Lin: CVE-2017-0627</li> 80 <li>Alibaba Inc. Yong Wang<a href="https://twitter.com/ThomasKing2014">@ThomasKing2014</a>: CVE-2017-0588</li> 81 <li>Qihoo 360 Technology Co. Ltd. IceSword Lab Yonggang Guo<a href="https://twitter.com/guoygang">@guoygang</a>: CVE-2016-10289CVE-2017-0465</li> 82 <li>Qihoo 360 Technology Co. Ltd. Vulpecker Team Yu Pan: CVE-2016-10282CVE-2017-0615</li> 83 <li>Qihoo 360 Technology Co. Ltd.Vulpecker Team Yu PanPeide Zhang: CVE-2017-0618CVE-2017-0625</li> 84 </ul> 85 86 <h2 id="2017-05-01-details"> 2017-05-01 </h2> 87 88 <p> 2017-05-01 CVE Google AOSP AOSP ID ID </p> 89 90 <h3 id="rce-in-mediaserver"></h3> 91 92 <p> </p> 93 94 <table> 95 <colgroup><col width="18%" /> 96 <col width="17%" /> 97 <col width="10%" /> 98 <col width="19%" /> 99 <col width="18%" /> 100 <col width="17%" /> 101 </colgroup><tbody><tr> 102 <th>CVE</th> 103 <th></th> 104 <th></th> 105 <th> Google </th> 106 <th> AOSP </th> 107 <th></th> 108 </tr> 109 <tr> 110 <td>CVE-2017-0587</td> 111 <td><a href="https://android.googlesource.com/platform/external/libmpeg2/+/a86eb798d077b9b25c8f8c77e3c02c2f287c1ce7">A-35219737</a></td> 112 <td></td> 113 <td></td> 114 <td>6.06.0.17.07.1.17.1.2</td> 115 <td>2017 1 4 </td> 116 </tr> 117 <tr> 118 <td>CVE-2017-0588</td> 119 <td><a href="https://android.googlesource.com/platform/frameworks/av/+/6f1d990ce0f116a205f467d9eb2082795e33872b">A-34618607</a></td> 120 <td></td> 121 <td></td> 122 <td>4.4.45.0.25.1.16.06.0.17.07.1.17.1.2</td> 123 <td>2017 1 21 </td> 124 </tr> 125 <tr> 126 <td>CVE-2017-0589</td> 127 <td><a href="https://android.googlesource.com/platform/external/libhevc/+/bcfc7124f6ef9f1ec128fb2e90de774a5b33d199">A-34897036</a></td> 128 <td></td> 129 <td></td> 130 <td>5.0.25.1.16.06.0.17.07.1.17.1.2</td> 131 <td>2017 2 1 </td> 132 </tr> 133 <tr> 134 <td>CVE-2017-0590</td> 135 <td><a href="https://android.googlesource.com/platform/external/libhevc/+/45c97f878bee15cd97262fe7f57ecea71990fed7">A-35039946</a></td> 136 <td></td> 137 <td></td> 138 <td>5.0.25.1.16.06.0.17.07.1.17.1.2</td> 139 <td>2017 2 6 </td> 140 </tr> 141 <tr> 142 <td>CVE-2017-0591</td> 143 <td><a href="https://android.googlesource.com/platform/external/libavc/+/5c3fd5d93a268abb20ff22f26009535b40db3c7d">A-34097672</a></td> 144 <td></td> 145 <td></td> 146 <td>6.06.0.17.07.1.17.1.2</td> 147 <td>Google </td> 148 </tr> 149 <tr> 150 <td>CVE-2017-0592</td> 151 <td><a href="https://android.googlesource.com/platform/frameworks/av/+/acc192347665943ca674acf117e4f74a88436922">A-34970788</a></td> 152 <td></td> 153 <td></td> 154 <td>4.4.45.0.25.1.16.06.0.17.07.1.17.1.2</td> 155 <td>Google </td> 156 </tr> 157 </tbody></table> 158 159 <h3 id="eop-in-framework-apis"> API </h3> 160 161 <p> API </p> 162 163 <table> 164 <colgroup><col width="18%" /> 165 <col width="17%" /> 166 <col width="10%" /> 167 <col width="19%" /> 168 <col width="18%" /> 169 <col width="17%" /> 170 </colgroup><tbody><tr> 171 <th>CVE</th> 172 <th></th> 173 <th></th> 174 <th> Google </th> 175 <th> AOSP </th> 176 <th></th> 177 </tr> 178 <tr> 179 <td>CVE-2017-0593</td> 180 <td><a href="https://android.googlesource.com/platform/frameworks/base/+/78efbc95412b8efa9a44d573f5767ae927927d48">A-34114230</a></td> 181 <td></td> 182 <td></td> 183 <td>6.06.0.17.07.1.17.1.2</td> 184 <td>2017 1 5 </td> 185 </tr> 186 </tbody></table> 187 188 <h3 id="eop-in-mediaserver"></h3> 189 190 <p></p> 191 192 <table> 193 <colgroup><col width="18%" /> 194 <col width="17%" /> 195 <col width="10%" /> 196 <col width="19%" /> 197 <col width="18%" /> 198 <col width="17%" /> 199 </colgroup><tbody><tr> 200 <th>CVE</th> 201 <th></th> 202 <th></th> 203 <th> Google </th> 204 <th> AOSP </th> 205 <th></th> 206 </tr> 207 <tr> 208 <td>CVE-2017-0594</td> 209 <td><a href="https://android.googlesource.com/platform/frameworks/av/+/594bf934384920618d2b6ce0bcda1f60144cb3eb">A-34617444</a></td> 210 <td></td> 211 <td></td> 212 <td>4.4.45.0.25.1.16.06.0.17.07.1.17.1.2</td> 213 <td>2017 1 22 </td> 214 </tr> 215 <tr> 216 <td>CVE-2017-0595</td> 217 <td><a href="https://android.googlesource.com/platform/frameworks/av/+/5443b57cc54f2e46b35246637be26a69e9f493e1">A-34705519</a></td> 218 <td></td> 219 <td></td> 220 <td>4.4.45.0.25.1.16.06.0.17.07.1.1</td> 221 <td>2017 1 24 </td> 222 </tr> 223 <tr> 224 <td>CVE-2017-0596</td> 225 <td><a href="https://android.googlesource.com/platform/frameworks/av/+/5443b57cc54f2e46b35246637be26a69e9f493e1">A-34749392</a></td> 226 <td></td> 227 <td></td> 228 <td>4.4.45.0.25.1.16.06.0.17.07.1.1</td> 229 <td>2017 1 24 </td> 230 </tr> 231 </tbody></table> 232 233 <h3 id="eop-in-audioserver"></h3> 234 235 <p></p> 236 237 <table> 238 <colgroup><col width="18%" /> 239 <col width="17%" /> 240 <col width="10%" /> 241 <col width="19%" /> 242 <col width="18%" /> 243 <col width="17%" /> 244 </colgroup><tbody><tr> 245 <th>CVE</th> 246 <th></th> 247 <th></th> 248 <th> Google </th> 249 <th> AOSP </th> 250 <th></th> 251 </tr> 252 <tr> 253 <td>CVE-2017-0597</td> 254 <td><a href="https://android.googlesource.com/platform/frameworks/av/+/a9188f89179a7edd301abaf37d644adf5d647a04">A-34749571</a></td> 255 <td></td> 256 <td></td> 257 <td>4.4.45.0.25.1.16.06.0.17.07.1.17.1.2</td> 258 <td>2017 1 25 </td> 259 </tr> 260 </tbody></table> 261 262 <h3 id="id-in-framework-apis"> API </h3> 263 264 <p> API </p> 265 266 <table> 267 <colgroup><col width="18%" /> 268 <col width="17%" /> 269 <col width="10%" /> 270 <col width="19%" /> 271 <col width="18%" /> 272 <col width="17%" /> 273 </colgroup><tbody><tr> 274 <th>CVE</th> 275 <th></th> 276 <th></th> 277 <th> Google </th> 278 <th> AOSP </th> 279 <th></th> 280 </tr> 281 <tr> 282 <td>CVE-2017-0598</td> 283 <td><a href="https://android.googlesource.com/platform/frameworks/base/+/4e110ab20bb91e945a17c6e166e14e2da9608f08">A-34128677</a> 284 [<a href="https://android.googlesource.com/platform/frameworks/base/+/d42e1204d5dddb78ec9d20d125951b59a8344f40">2</a>]</td> 285 <td></td> 286 <td></td> 287 <td>4.4.45.0.25.1.16.06.0.17.07.1.17.1.2</td> 288 <td>2017 1 6 </td> 289 </tr> 290 </tbody></table> 291 292 <h3 id="dos-in-mediaserver"></h3> 293 294 <p></p> 295 296 <table> 297 <colgroup><col width="18%" /> 298 <col width="17%" /> 299 <col width="10%" /> 300 <col width="19%" /> 301 <col width="18%" /> 302 <col width="17%" /> 303 </colgroup><tbody><tr> 304 <th>CVE</th> 305 <th></th> 306 <th></th> 307 <th> Google </th> 308 <th> AOSP </th> 309 <th></th> 310 </tr> 311 <tr> 312 <td>CVE-2017-0599</td> 313 <td><a href="https://android.googlesource.com/platform/external/libhevc/+/a1424724a00d62ac5efa0e27953eed66850d662f">A-34672748</a></td> 314 <td></td> 315 <td></td> 316 <td>6.06.0.17.07.1.17.1.2</td> 317 <td>2017 1 23 </td> 318 </tr> 319 <tr> 320 <td>CVE-2017-0600</td> 321 <td><a href="https://android.googlesource.com/platform/frameworks/av/+/961e5ac5788b52304e64b9a509781beaf5201fb0">A-35269635</a></td> 322 <td></td> 323 <td></td> 324 <td>4.4.45.0.25.1.16.06.0.17.07.1.17.1.2</td> 325 <td>2017 2 10 </td> 326 </tr> 327 </tbody></table> 328 329 <h3 id="eop-in-bluetooth">Bluetooth </h3> 330 331 <p>Bluetooth Bluetooth </p> 332 333 <table> 334 <colgroup><col width="18%" /> 335 <col width="17%" /> 336 <col width="10%" /> 337 <col width="19%" /> 338 <col width="18%" /> 339 <col width="17%" /> 340 </colgroup><tbody><tr> 341 <th>CVE</th> 342 <th></th> 343 <th></th> 344 <th> Google </th> 345 <th> AOSP </th> 346 <th></th> 347 </tr> 348 <tr> 349 <td>CVE-2017-0601</td> 350 <td><a href="https://android.googlesource.com/platform/frameworks/base/+/667d2cbe3eb1450f273a4f6595ccef35e1f0fe4b">A-35258579</a></td> 351 <td></td> 352 <td></td> 353 <td>7.07.1.17.1.2</td> 354 <td>2017 2 9 </td> 355 </tr> 356 </tbody></table> 357 358 <h3 id="id-in-file-based-encryption"></h3> 359 360 <p> </p> 361 362 <table> 363 <colgroup><col width="18%" /> 364 <col width="17%" /> 365 <col width="10%" /> 366 <col width="19%" /> 367 <col width="18%" /> 368 <col width="17%" /> 369 </colgroup><tbody><tr> 370 <th>CVE</th> 371 <th></th> 372 <th></th> 373 <th> Google </th> 374 <th> AOSP </th> 375 <th></th> 376 </tr> 377 <tr> 378 <td>CVE-2017-0493</td> 379 <td><a href="https://android.googlesource.com/platform/frameworks/base/+/e4cefbf4fce458489b5f1bebc79dfaf566bcc5d5">A-32793550</a> 380 [<a href="https://android.googlesource.com/platform/frameworks/base/+/f806d65e615b942c268a5f68d44bde9d55634972">2</a>]</td> 381 <td></td> 382 <td></td> 383 <td>7.07.1.1</td> 384 <td>2016 11 9 </td> 385 </tr> 386 </tbody></table> 387 388 <h3 id="id-in-bluetooth">Bluetooth </h3> 389 390 <p>Bluetooth </p> 391 392 <table> 393 <colgroup><col width="18%" /> 394 <col width="17%" /> 395 <col width="10%" /> 396 <col width="19%" /> 397 <col width="18%" /> 398 <col width="17%" /> 399 </colgroup><tbody><tr> 400 <th>CVE</th> 401 <th></th> 402 <th></th> 403 <th> Google </th> 404 <th> AOSP </th> 405 <th></th> 406 </tr> 407 <tr> 408 <td>CVE-2017-0602</td> 409 <td><a href="https://android.googlesource.com/platform/system/bt/+/a4875a49404c544134df37022ae587a4a3321647">A-34946955</a></td> 410 <td></td> 411 <td></td> 412 <td>4.4.45.0.25.1.16.06.0.17.07.1.17.1.2</td> 413 <td>2016 12 5 </td> 414 </tr> 415 </tbody></table> 416 417 <h3 id="id-in-openssl-&-boringssl">OpenSSL BoringSSL </h3> 418 419 <p>OpenSSL BoringSSL </p> 420 421 <table> 422 <colgroup><col width="18%" /> 423 <col width="17%" /> 424 <col width="10%" /> 425 <col width="19%" /> 426 <col width="18%" /> 427 <col width="17%" /> 428 </colgroup><tbody><tr> 429 <th>CVE</th> 430 <th></th> 431 <th></th> 432 <th> Google </th> 433 <th> AOSP </th> 434 <th></th> 435 </tr> 436 <tr> 437 <td>CVE-2016-7056</td> 438 <td><a href="https://android.googlesource.com/platform/external/boringssl/+/13179a8e75fee98740b5ce728752aa7294b3e32d">A-33752052</a></td> 439 <td></td> 440 <td></td> 441 <td>4.4.45.0.25.1.16.06.0.17.07.1.17.1.2</td> 442 <td>2016 12 19 </td> 443 </tr> 444 </tbody></table> 445 446 <h3 id="dos-in-mediaserver-2"></h3> 447 448 <p></p> 449 450 <table> 451 <colgroup><col width="18%" /> 452 <col width="17%" /> 453 <col width="10%" /> 454 <col width="19%" /> 455 <col width="18%" /> 456 <col width="17%" /> 457 </colgroup><tbody><tr> 458 <th>CVE</th> 459 <th></th> 460 <th></th> 461 <th> Google </th> 462 <th> AOSP </th> 463 <th></th> 464 </tr> 465 <tr> 466 <td>CVE-2017-0603</td> 467 <td><a href="https://android.googlesource.com/platform/frameworks/av/+/36b04932bb93cc3269279282686b439a17a89920">A-35763994</a></td> 468 <td></td> 469 <td></td> 470 <td>4.4.45.0.25.1.16.06.0.17.07.1.17.1.2</td> 471 <td>2017 2 23 </td> 472 </tr> 473 </tbody></table> 474 475 <h3 id="dos-in-mediaserver-3"></h3> 476 477 <p></p> 478 479 <table> 480 <colgroup><col width="18%" /> 481 <col width="17%" /> 482 <col width="10%" /> 483 <col width="19%" /> 484 <col width="18%" /> 485 <col width="17%" /> 486 </colgroup><tbody><tr> 487 <th>CVE</th> 488 <th></th> 489 <th></th> 490 <th> Google </th> 491 <th> AOSP </th> 492 <th></th> 493 </tr> 494 <tr> 495 <td>CVE-2017-0635</td> 496 <td><a href="https://android.googlesource.com/platform/frameworks/av/+/523f6b49c1a2289161f40cf9fe80b92e592e9441">A-35467107</a></td> 497 <td></td> 498 <td></td> 499 <td>7.07.1.17.1.2</td> 500 <td>2017 2 16 </td> 501 </tr> 502 </tbody></table> 503 504 <h2 id="2017-05-05-details"> 2017-05-05 </h2> 505 506 <p> 2017-05-05 CVE Google AOSP AOSP ID ID </p> 507 508 <h3 id="rce-in-giflib">GIFLIB </h3> 509 510 <p>GIFLIB </p> 511 512 <table> 513 <colgroup><col width="18%" /> 514 <col width="17%" /> 515 <col width="10%" /> 516 <col width="19%" /> 517 <col width="18%" /> 518 <col width="17%" /> 519 </colgroup><tbody><tr> 520 <th>CVE</th> 521 <th></th> 522 <th></th> 523 <th> Google </th> 524 <th> AOSP </th> 525 <th></th> 526 </tr> 527 <tr> 528 <td>CVE-2015-7555</td> 529 <td><a href="https://android.googlesource.com/platform/external/giflib/+/dc07290edccc2c3fc4062da835306f809cea1fdc">A-34697653</a></td> 530 <td></td> 531 <td></td> 532 <td>4.4.45.0.25.1.16.06.0.17.07.1.17.1.2</td> 533 <td>2016 4 13 </td> 534 </tr> 535 </tbody></table> 536 537 <h3 id="eop-in-mediatek-touchscreen-driver">MediaTek </h3> 538 539 <p>MediaTek </p> 540 541 <table> 542 <colgroup><col width="19%" /> 543 <col width="20%" /> 544 <col width="10%" /> 545 <col width="23%" /> 546 <col width="17%" /> 547 </colgroup><tbody><tr> 548 <th>CVE</th> 549 <th></th> 550 <th></th> 551 <th> Google </th> 552 <th></th> 553 </tr> 554 <tr> 555 <td>CVE-2016-10274</td> 556 <td>A-30202412*<br /> 557 M-ALPS02897901</td> 558 <td></td> 559 <td>**</td> 560 <td>2016 7 16 </td> 561 </tr> 562 </tbody></table> 563 564 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 565 566 <p>** Android 7.1.1 Google </p> 567 568 <h3 id="eop-in-qualcomm-bootloader">Qualcomm </h3> 569 570 <p>Qualcomm </p> 571 572 <table> 573 <colgroup><col width="19%" /> 574 <col width="20%" /> 575 <col width="10%" /> 576 <col width="23%" /> 577 <col width="17%" /> 578 </colgroup><tbody><tr> 579 <th>CVE</th> 580 <th></th> 581 <th></th> 582 <th> Google </th> 583 <th></th> 584 </tr> 585 <tr> 586 <td>CVE-2016-10275</td> 587 <td>A-34514954<br /> 588 <a href="https://source.codeaurora.org/quic/la//kernel/lk/commit/?id=1a0a15c380e11fc46f8d8706ea5ae22b752bdd0b"> 589 QC-CR#1009111</a></td> 590 <td></td> 591 <td>Nexus 5XNexus 6PixelPixel XLAndroid One</td> 592 <td>2016 9 13 </td> 593 </tr> 594 <tr> 595 <td>CVE-2016-10276</td> 596 <td>A-32952839<br /> 597 <a href="https://source.codeaurora.org/quic/la//kernel/lk/commit/?id=5dac431748027e8b50a5c4079967def4ea53ad64"> 598 QC-CR#1094105</a></td> 599 <td></td> 600 <td>Nexus 5XNexus 6PPixelPixel XL</td> 601 <td>2016 11 16 </td> 602 </tr> 603 </tbody></table> 604 605 <h3 id="eop-in-kernel-sound-subsystem"> </h3> 606 607 <p> </p> 608 609 <table> 610 <colgroup><col width="19%" /> 611 <col width="20%" /> 612 <col width="10%" /> 613 <col width="23%" /> 614 <col width="17%" /> 615 </colgroup><tbody><tr> 616 <th>CVE</th> 617 <th></th> 618 <th></th> 619 <th> Google </th> 620 <th></th> 621 </tr> 622 <tr> 623 <td>CVE-2016-9794</td> 624 <td>A-34068036<br /> 625 <a href="https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=a27178e05b7c332522df40904f27674e36ee3757"> 626 </a></td> 627 <td></td> 628 <td>Nexus 5XNexus 6Nexus 6PNexus 9PixelPixel XLPixel CAndroid OneNexus Player</td> 629 <td>2016 12 3 </td> 630 </tr> 631 </tbody></table> 632 633 <h3 id="eop-in-motorola-bootloader">Motorola </h3> 634 635 <p>Motorola </p> 636 637 <table> 638 <colgroup><col width="19%" /> 639 <col width="20%" /> 640 <col width="10%" /> 641 <col width="23%" /> 642 <col width="17%" /> 643 </colgroup><tbody><tr> 644 <th>CVE</th> 645 <th></th> 646 <th></th> 647 <th> Google </th> 648 <th></th> 649 </tr> 650 <tr> 651 <td>CVE-2016-10277</td> 652 <td>A-33840490*<br /> 653 </td> 654 <td></td> 655 <td>Nexus 6</td> 656 <td>2016 12 21 </td> 657 </tr> 658 </tbody></table> 659 660 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 661 662 <h3 id="eop-in-nvidia-video-driver">NVIDIA </h3> 663 664 <p>NVIDIA </p> 665 666 <table> 667 <colgroup><col width="19%" /> 668 <col width="20%" /> 669 <col width="10%" /> 670 <col width="23%" /> 671 <col width="17%" /> 672 </colgroup><tbody><tr> 673 <th>CVE</th> 674 <th></th> 675 <th></th> 676 <th> Google </th> 677 <th></th> 678 </tr> 679 <tr> 680 <td>CVE-2017-0331</td> 681 <td>A-34113000*<br /> 682 N-CVE-2017-0331</td> 683 <td></td> 684 <td>Nexus 9</td> 685 <td>2017 1 4 </td> 686 </tr> 687 </tbody></table> 688 689 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 690 691 <h3 id="eop-in-qualcomm-power-driver">Qualcomm </h3> 692 693 <p> Qualcomm </p> 694 695 <table> 696 <colgroup><col width="19%" /> 697 <col width="20%" /> 698 <col width="10%" /> 699 <col width="23%" /> 700 <col width="17%" /> 701 </colgroup><tbody><tr> 702 <th>CVE</th> 703 <th></th> 704 <th></th> 705 <th> Google </th> 706 <th></th> 707 </tr> 708 <tr> 709 <td>CVE-2017-0604</td> 710 <td>A-35392981<br /> 711 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=6975e2dd5f37de965093ba3a8a08635a77a960f7"> 712 QC-CR#826589</a></td> 713 <td></td> 714 <td>*</td> 715 <td>2017 2 15 </td> 716 </tr> 717 </tbody></table> 718 719 <p>* Android 7.1.1 Google </p> 720 721 <h3 id="eop-in-kernel-trace-subsystem"> </h3> 722 723 <p> </p> 724 725 <table> 726 <colgroup><col width="19%" /> 727 <col width="20%" /> 728 <col width="10%" /> 729 <col width="23%" /> 730 <col width="17%" /> 731 </colgroup><tbody><tr> 732 <th>CVE</th> 733 <th></th> 734 <th></th> 735 <th> Google </th> 736 <th></th> 737 </tr> 738 <tr> 739 <td>CVE-2017-0605</td> 740 <td>A-35399704<br /> 741 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.10/commit/?id=2161ae9a70b12cf18ac8e5952a20161ffbccb477"> 742 QC-CR#1048480</a></td> 743 <td></td> 744 <td>Nexus 5XNexus 6Nexus 6PNexus 9PixelPixel XLPixel CAndroid OneNexus Player</td> 745 <td>2017 2 15 </td> 746 </tr> 747 </tbody></table> 748 749 <h3 id="vulnerabilities-in-qualcomm-components">Qualcomm </h3> 750 751 <p>Qualcomm Qualcomm AMSS 2016 8 9 10 12 </p> 752 753 <table> 754 <colgroup><col width="19%" /> 755 <col width="20%" /> 756 <col width="10%" /> 757 <col width="23%" /> 758 <col width="17%" /> 759 </colgroup><tbody><tr> 760 <th>CVE</th> 761 <th></th> 762 <th></th> 763 <th> Google </th> 764 <th></th> 765 </tr> 766 <tr> 767 <td>CVE-2016-10240</td> 768 <td>A-32578446**<br /> 769 QC-CR#955710</td> 770 <td></td> 771 <td>Nexus 6P</td> 772 <td>Qualcomm </td> 773 </tr> 774 <tr> 775 <td>CVE-2016-10241</td> 776 <td>A-35436149**<br /> 777 QC-CR#1068577</td> 778 <td></td> 779 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XL</td> 780 <td>Qualcomm </td> 781 </tr> 782 <tr> 783 <td>CVE-2016-10278</td> 784 <td>A-31624008**<br /> 785 QC-CR#1043004</td> 786 <td></td> 787 <td>PixelPixel XL</td> 788 <td>Qualcomm </td> 789 </tr> 790 <tr> 791 <td>CVE-2016-10279</td> 792 <td>A-31624421**<br /> 793 QC-CR#1031821</td> 794 <td></td> 795 <td>PixelPixel XL</td> 796 <td>Qualcomm </td> 797 </tr> 798 </tbody></table> 799 800 <p>* </p> 801 802 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 803 804 <p>*** Android 7.1.1 Google </p> 805 806 <h3 id="rce-in-libxml2">libxml2 </h3> 807 808 <p>libxml2 </p> 809 810 <table> 811 <colgroup><col width="18%" /> 812 <col width="17%" /> 813 <col width="10%" /> 814 <col width="19%" /> 815 <col width="18%" /> 816 <col width="17%" /> 817 </colgroup><tbody><tr> 818 <th>CVE</th> 819 <th></th> 820 <th></th> 821 <th> Google </th> 822 <th> AOSP </th> 823 <th></th> 824 </tr> 825 <tr> 826 <td>CVE-2016-5131</td> 827 <td>A-32956747*</td> 828 <td></td> 829 <td>**</td> 830 <td>4.4.45.0.25.1.16.06.0.17.0</td> 831 <td>2016 7 23 </td> 832 </tr> 833 </tbody></table> 834 835 <p>* <a href="https://developers.google.com/android/drivers">Google </a> Nexus </p> 836 837 <p>** Android 7.1.1 Google </p> 838 839 <h3 id="eop-in-mediatek-thermal-driver">MediaTek </h3> 840 841 <p>MediaTek </p> 842 843 <table> 844 <colgroup><col width="19%" /> 845 <col width="20%" /> 846 <col width="10%" /> 847 <col width="23%" /> 848 <col width="17%" /> 849 </colgroup><tbody><tr> 850 <th>CVE</th> 851 <th></th> 852 <th></th> 853 <th> Google </th> 854 <th></th> 855 </tr> 856 <tr> 857 <td>CVE-2016-10280</td> 858 <td>A-28175767*<br /> 859 M-ALPS02696445</td> 860 <td></td> 861 <td>**</td> 862 <td>2016 4 11 </td> 863 </tr> 864 <tr> 865 <td>CVE-2016-10281</td> 866 <td>A-28175647*<br /> 867 M-ALPS02696475</td> 868 <td></td> 869 <td>**</td> 870 <td>2016 4 11 </td> 871 </tr> 872 <tr> 873 <td>CVE-2016-10282</td> 874 <td>A-33939045*<br /> 875 M-ALPS03149189</td> 876 <td></td> 877 <td>**</td> 878 <td>2016 12 27 </td> 879 </tr> 880 </tbody></table> 881 882 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 883 884 <p>** Android 7.1.1 Google </p> 885 886 <h3 id="eop-in-qualcomm-wi-fi-driver">Qualcomm Wi-Fi </h3> 887 888 <p>Qualcomm Wi-Fi </p> 889 890 <table> 891 <colgroup><col width="19%" /> 892 <col width="20%" /> 893 <col width="10%" /> 894 <col width="23%" /> 895 <col width="17%" /> 896 </colgroup><tbody><tr> 897 <th>CVE</th> 898 <th></th> 899 <th></th> 900 <th> Google </th> 901 <th></th> 902 </tr> 903 <tr> 904 <td>CVE-2016-10283</td> 905 <td>A-32094986<br /> 906 <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=93863644b4547324309613361d70ad9dc91f8dfd"> 907 QC-CR#2002052</a></td> 908 <td></td> 909 <td>Nexus 5XPixelPixel XLAndroid One</td> 910 <td>2016 10 11 </td> 911 </tr> 912 </tbody></table> 913 914 <h3 id="eop-in-qualcomm-video-driver">Qualcomm </h3> 915 916 <p>Qualcomm </p> 917 918 <table> 919 <colgroup><col width="19%" /> 920 <col width="20%" /> 921 <col width="10%" /> 922 <col width="23%" /> 923 <col width="17%" /> 924 </colgroup><tbody><tr> 925 <th>CVE</th> 926 <th></th> 927 <th></th> 928 <th> Google </th> 929 <th></th> 930 </tr> 931 <tr> 932 <td>CVE-2016-10284</td> 933 <td>A-32402303*<br /> 934 QC-CR#2000664</td> 935 <td></td> 936 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 937 <td>2016 10 24 </td> 938 </tr> 939 <tr> 940 <td>CVE-2016-10285</td> 941 <td>A-33752702<br /> 942 <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=67dfd3a65336e0b3f55ee83d6312321dc5f2a6f9"> 943 QC-CR#1104899</a></td> 944 <td></td> 945 <td>PixelPixel XL</td> 946 <td>2016 12 19 </td> 947 </tr> 948 <tr> 949 <td>CVE-2016-10286</td> 950 <td>A-35400904<br /> 951 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=5d30a3d0dc04916ddfb972bfc52f8e636642f999"> 952 QC-CR#1090237</a></td> 953 <td></td> 954 <td>PixelPixel XL</td> 955 <td>2017 2 15 </td> 956 </tr> 957 </tbody></table> 958 959 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 960 961 <h3 id="eop-in-kernel-performance-subsystem"> </h3> 962 963 <p> </p> 964 965 <table> 966 <colgroup><col width="19%" /> 967 <col width="20%" /> 968 <col width="10%" /> 969 <col width="23%" /> 970 <col width="17%" /> 971 </colgroup><tbody><tr> 972 <th>CVE</th> 973 <th></th> 974 <th></th> 975 <th> Google </th> 976 <th></th> 977 </tr> 978 <tr> 979 <td>CVE-2015-9004</td> 980 <td>A-34515362<br /> 981 <a href="https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=c3c87e770458aa004bd7ed3f29945ff436fd6511"> 982 </a></td> 983 <td></td> 984 <td>Nexus 5XNexus 6Nexus 6PNexus 9PixelPixel XLPixel CAndroid OneNexus Player</td> 985 <td>2016 11 23 </td> 986 </tr> 987 </tbody></table> 988 989 <h3 id="eop-in-qualcomm-sound-driver">Qualcomm </h3> 990 991 <p>Qualcomm </p> 992 993 <table> 994 <colgroup><col width="19%" /> 995 <col width="20%" /> 996 <col width="10%" /> 997 <col width="23%" /> 998 <col width="17%" /> 999 </colgroup><tbody><tr> 1000 <th>CVE</th> 1001 <th></th> 1002 <th></th> 1003 <th> Google </th> 1004 <th></th> 1005 </tr> 1006 <tr> 1007 <td>CVE-2016-10287</td> 1008 <td>A-33784446<br /> 1009 <a href="https://www.codeaurora.org/gitweb/quic/la/?p=kernel/msm-4.4.git;a=commit;h=937bc9e644180e258c68662095861803f7ba4ded"> 1010 QC-CR#1112751</a></td> 1011 <td></td> 1012 <td>Nexus 5XNexus 6PPixelPixel XLAndroid One</td> 1013 <td>2016 12 20 </td> 1014 </tr> 1015 <tr> 1016 <td>CVE-2017-0606</td> 1017 <td>A-34088848<br /> 1018 <a href="https://www.codeaurora.org/gitweb/quic/la/?p=kernel/msm-4.4.git;a=commit;h=d3237316314c3d6f75a58192971f66e3822cd250"> 1019 QC-CR#1116015</a></td> 1020 <td></td> 1021 <td>Nexus 5XNexus 6PPixelPixel XLAndroid One</td> 1022 <td>2017 1 3 </td> 1023 </tr> 1024 <tr> 1025 <td>CVE-2016-5860</td> 1026 <td>A-34623424<br /> 1027 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=9f91ae0d7203714fc39ae78e1f1c4fd71ed40498"> 1028 QC-CR#1100682</a></td> 1029 <td></td> 1030 <td>PixelPixel XL</td> 1031 <td>2017 1 22 </td> 1032 </tr> 1033 <tr> 1034 <td>CVE-2016-5867</td> 1035 <td>A-35400602<br /> 1036 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=065360da7147003aed8f59782b7652d565f56be5"> 1037 QC-CR#1095947</a></td> 1038 <td></td> 1039 <td>*</td> 1040 <td>2017 2 15 </td> 1041 </tr> 1042 <tr> 1043 <td>CVE-2017-0607</td> 1044 <td>A-35400551<br /> 1045 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=b003c8d5407773d3aa28a48c9841e4c124da453d"> 1046 QC-CR#1085928</a></td> 1047 <td></td> 1048 <td>PixelPixel XL</td> 1049 <td>2017 2 15 </td> 1050 </tr> 1051 <tr> 1052 <td>CVE-2017-0608</td> 1053 <td>A-35400458<br /> 1054 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=b66f442dd97c781e873e8f7b248e197f86fd2980"> 1055 QC-CR#1098363</a></td> 1056 <td></td> 1057 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 1058 <td>2017 2 15 </td> 1059 </tr> 1060 <tr> 1061 <td>CVE-2017-0609</td> 1062 <td>A-35399801<br /> 1063 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=38a83df036084c00e8c5a4599c8ee7880b4ee567"> 1064 QC-CR#1090482</a></td> 1065 <td></td> 1066 <td>Nexus 5XNexus 6PPixelPixel XLAndroid One</td> 1067 <td>2017 2 15 </td> 1068 </tr> 1069 <tr> 1070 <td>CVE-2016-5859</td> 1071 <td>A-35399758<br /> 1072 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=97fdb441a9fb330a76245e473bc1a2155c809ebe"> 1073 QC-CR#1096672</a></td> 1074 <td></td> 1075 <td>*</td> 1076 <td>2017 2 15 </td> 1077 </tr> 1078 <tr> 1079 <td>CVE-2017-0610</td> 1080 <td>A-35399404<br /> 1081 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=65009746a6e649779f73d665934561ea983892fe"> 1082 QC-CR#1094852</a></td> 1083 <td></td> 1084 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 1085 <td>2017 2 15 </td> 1086 </tr> 1087 <tr> 1088 <td>CVE-2017-0611</td> 1089 <td>A-35393841<br /> 1090 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=1aa5df9246557a98181f03e98530ffd509b954c8"> 1091 QC-CR#1084210</a></td> 1092 <td></td> 1093 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 1094 <td>2017 2 15 </td> 1095 </tr> 1096 <tr> 1097 <td>CVE-2016-5853</td> 1098 <td>A-35392629<br /> 1099 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=a8f3b894de319718aecfc2ce9c691514696805be"> 1100 QC-CR#1102987</a></td> 1101 <td></td> 1102 <td>*</td> 1103 <td>2017 2 15 </td> 1104 </tr> 1105 </tbody></table> 1106 1107 <p>* Android 7.1.1 Google </p> 1108 1109 <h3 id="eop-in-qualcomm-led-driver">Qualcomm LED </h3> 1110 1111 <p>Qualcomm LED </p> 1112 1113 <table> 1114 <colgroup><col width="19%" /> 1115 <col width="20%" /> 1116 <col width="10%" /> 1117 <col width="23%" /> 1118 <col width="17%" /> 1119 </colgroup><tbody><tr> 1120 <th>CVE</th> 1121 <th></th> 1122 <th></th> 1123 <th> Google </th> 1124 <th></th> 1125 </tr> 1126 <tr> 1127 <td>CVE-2016-10288</td> 1128 <td>A-33863909<br /> 1129 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=db2cdc95204bc404f03613d5dd7002251fb33660"> 1130 QC-CR#1109763</a></td> 1131 <td></td> 1132 <td>PixelPixel XL</td> 1133 <td>2016 12 23 </td> 1134 </tr> 1135 </tbody></table> 1136 1137 <h3 id="eop-in-qualcomm-crypto-driver">Qualcomm crypto </h3> 1138 1139 <p>Qualcomm crypto </p> 1140 1141 <table> 1142 <colgroup><col width="19%" /> 1143 <col width="20%" /> 1144 <col width="10%" /> 1145 <col width="23%" /> 1146 <col width="17%" /> 1147 </colgroup><tbody><tr> 1148 <th>CVE</th> 1149 <th></th> 1150 <th></th> 1151 <th> Google </th> 1152 <th></th> 1153 </tr> 1154 <tr> 1155 <td>CVE-2016-10289</td> 1156 <td>A-33899710<br /> 1157 <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=a604e6f3889ccc343857532b63dea27603381816"> 1158 QC-CR#1116295</a></td> 1159 <td></td> 1160 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 1161 <td>2016 12 24 </td> 1162 </tr> 1163 </tbody></table> 1164 1165 <h3 id="eop-in-qualcomm-shared-memory-driver">Qualcomm </h3> 1166 1167 <p>Qualcomm </p> 1168 1169 <table> 1170 <colgroup><col width="19%" /> 1171 <col width="20%" /> 1172 <col width="10%" /> 1173 <col width="23%" /> 1174 <col width="17%" /> 1175 </colgroup><tbody><tr> 1176 <th>CVE</th> 1177 <th></th> 1178 <th></th> 1179 <th> Google </th> 1180 <th></th> 1181 </tr> 1182 <tr> 1183 <td>CVE-2016-10290</td> 1184 <td>A-33898330<br /> 1185 <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=a5e46d8635a2e28463b365aacdeab6750abd0d49"> 1186 QC-CR#1109782</a></td> 1187 <td></td> 1188 <td>Nexus 5XNexus 6PPixelPixel XL</td> 1189 <td>2016 12 24 </td> 1190 </tr> 1191 </tbody></table> 1192 1193 <h3 id="eop-in-qualcomm-slimbus-driver">Qualcomm Slimbus </h3> 1194 1195 <p>Qualcomm Slimbus </p> 1196 1197 <table> 1198 <colgroup><col width="19%" /> 1199 <col width="20%" /> 1200 <col width="10%" /> 1201 <col width="23%" /> 1202 <col width="17%" /> 1203 </colgroup><tbody><tr> 1204 <th>CVE</th> 1205 <th></th> 1206 <th></th> 1207 <th> Google </th> 1208 <th></th> 1209 </tr> 1210 <tr> 1211 <td>CVE-2016-10291</td> 1212 <td>A-34030871<br /> 1213 <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=a225074c0494ca8125ca0ac2f9ebc8a2bd3612de"> 1214 QC-CR#986837</a></td> 1215 <td></td> 1216 <td>Nexus 5XNexus 6Nexus 6PAndroid One</td> 1217 <td>2016 12 31 </td> 1218 </tr> 1219 </tbody></table> 1220 1221 <h3 id="eop-in-qualcomm-adsprpc-driver">Qualcomm ADSPRPC </h3> 1222 1223 <p>Qualcomm ADSPRPC </p> 1224 1225 <table> 1226 <colgroup><col width="19%" /> 1227 <col width="20%" /> 1228 <col width="10%" /> 1229 <col width="23%" /> 1230 <col width="17%" /> 1231 </colgroup><tbody><tr> 1232 <th>CVE</th> 1233 <th></th> 1234 <th></th> 1235 <th> Google </th> 1236 <th></th> 1237 </tr> 1238 <tr> 1239 <td>CVE-2017-0465</td> 1240 <td>A-34112914<br /> 1241 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=3823f0f8d0bbbbd675a42a54691f4051b3c7e544"> 1242 QC-CR#1110747</a></td> 1243 <td></td> 1244 <td>Nexus 5XNexus 6PPixelPixel XLAndroid One</td> 1245 <td>2017 1 5 </td> 1246 </tr> 1247 </tbody></table> 1248 1249 <h3 id="eop-in-qualcomm-secure-execution-environment-communicator-driver">Qualcomm Secure Execution Environment Communicator </h3> 1250 1251 <p>Qualcomm Secure Execution Environment Communicator </p> 1252 1253 <table> 1254 <colgroup><col width="19%" /> 1255 <col width="20%" /> 1256 <col width="10%" /> 1257 <col width="23%" /> 1258 <col width="17%" /> 1259 </colgroup><tbody><tr> 1260 <th>CVE</th> 1261 <th></th> 1262 <th></th> 1263 <th> Google </th> 1264 <th></th> 1265 </tr> 1266 <tr> 1267 <td>CVE-2017-0612</td> 1268 <td>A-34389303<br /> 1269 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=05efafc998dc86c3b75af9803ca71255ddd7a8eb"> 1270 QC-CR#1061845</a></td> 1271 <td></td> 1272 <td>PixelPixel XL</td> 1273 <td>2017 1 10 </td> 1274 </tr> 1275 <tr> 1276 <td>CVE-2017-0613</td> 1277 <td>A-35400457<br /> 1278 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=b108c651cae9913da1ab163cb4e5f7f2db87b747"> 1279 QC-CR#1086140</a></td> 1280 <td></td> 1281 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 1282 <td>2017 2 15 </td> 1283 </tr> 1284 <tr> 1285 <td>CVE-2017-0614</td> 1286 <td>A-35399405<br /> 1287 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=fc2ae27eb9721a0ce050c2062734fec545cda604"> 1288 QC-CR#1080290</a></td> 1289 <td></td> 1290 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 1291 <td>2017 2 15 </td> 1292 </tr> 1293 </tbody></table> 1294 1295 <h3 id="eop-in-mediatek-power-driver">MediaTek </h3> 1296 1297 <p>MediaTek </p> 1298 1299 <table> 1300 <colgroup><col width="19%" /> 1301 <col width="20%" /> 1302 <col width="10%" /> 1303 <col width="23%" /> 1304 <col width="17%" /> 1305 </colgroup><tbody><tr> 1306 <th>CVE</th> 1307 <th></th> 1308 <th></th> 1309 <th> Google </th> 1310 <th></th> 1311 </tr> 1312 <tr> 1313 <td>CVE-2017-0615</td> 1314 <td>A-34259126*<br /> 1315 M-ALPS03150278</td> 1316 <td></td> 1317 <td>**</td> 1318 <td>2017 1 12 </td> 1319 </tr> 1320 </tbody></table> 1321 1322 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 1323 1324 <p>** Android 7.1.1 Google </p> 1325 1326 <h3 id="eop-in-mediatek-system-management-interrupt-driver">MediaTek </h3> 1327 1328 <p>MediaTek </p> 1329 1330 <table> 1331 <colgroup><col width="19%" /> 1332 <col width="20%" /> 1333 <col width="10%" /> 1334 <col width="23%" /> 1335 <col width="17%" /> 1336 </colgroup><tbody><tr> 1337 <th>CVE</th> 1338 <th></th> 1339 <th></th> 1340 <th> Google </th> 1341 <th></th> 1342 </tr> 1343 <tr> 1344 <td>CVE-2017-0616</td> 1345 <td>A-34470286*<br /> 1346 M-ALPS03149160</td> 1347 <td></td> 1348 <td>**</td> 1349 <td>2017 1 19 </td> 1350 </tr> 1351 </tbody></table> 1352 1353 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 1354 1355 <p>** Android 7.1.1 Google </p> 1356 1357 <h3 id="eop-in-mediatek-video-driver">MediaTek </h3> 1358 1359 <p>MediaTek </p> 1360 1361 <table> 1362 <colgroup><col width="19%" /> 1363 <col width="20%" /> 1364 <col width="10%" /> 1365 <col width="23%" /> 1366 <col width="17%" /> 1367 </colgroup><tbody><tr> 1368 <th>CVE</th> 1369 <th></th> 1370 <th></th> 1371 <th> Google </th> 1372 <th></th> 1373 </tr> 1374 <tr> 1375 <td>CVE-2017-0617</td> 1376 <td>A-34471002*<br /> 1377 M-ALPS03149173</td> 1378 <td></td> 1379 <td>**</td> 1380 <td>2017 1 19 </td> 1381 </tr> 1382 </tbody></table> 1383 1384 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 1385 1386 <p>** Android 7.1.1 Google </p> 1387 1388 <h3 id="eop-in-mediatek-command-queue-driver">MediaTek </h3> 1389 1390 <p>MediaTek </p> 1391 1392 <table> 1393 <colgroup><col width="19%" /> 1394 <col width="20%" /> 1395 <col width="10%" /> 1396 <col width="23%" /> 1397 <col width="17%" /> 1398 </colgroup><tbody><tr> 1399 <th>CVE</th> 1400 <th></th> 1401 <th></th> 1402 <th> Google </th> 1403 <th></th> 1404 </tr> 1405 <tr> 1406 <td>CVE-2017-0618</td> 1407 <td>A-35100728*<br /> 1408 M-ALPS03161536</td> 1409 <td></td> 1410 <td>**</td> 1411 <td>2017 2 7 </td> 1412 </tr> 1413 </tbody></table> 1414 1415 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 1416 1417 <p>** Android 7.1.1 Google </p> 1418 1419 <h3 id="eop-in-qualcomm-pin-controller-driver">Qualcomm </h3> 1420 1421 <p>Qualcomm </p> 1422 1423 <table> 1424 <colgroup><col width="19%" /> 1425 <col width="20%" /> 1426 <col width="10%" /> 1427 <col width="23%" /> 1428 <col width="17%" /> 1429 </colgroup><tbody><tr> 1430 <th>CVE</th> 1431 <th></th> 1432 <th></th> 1433 <th> Google </th> 1434 <th></th> 1435 </tr> 1436 <tr> 1437 <td>CVE-2017-0619</td> 1438 <td>A-35401152<br /> 1439 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.14/commit/?id=72f67b29a9c5e6e8d3c34751600c749c5f5e13e1"> 1440 QC-CR#826566</a></td> 1441 <td></td> 1442 <td>Nexus 6Android One</td> 1443 <td>2017 2 15 </td> 1444 </tr> 1445 </tbody></table> 1446 1447 <h3 id="eop-in-qualcomm-secure-channel-manager-driver">Qualcomm Secure Channel Manager </h3> 1448 1449 <p>Qualcomm Secure Channel Manager </p> 1450 1451 <table> 1452 <colgroup><col width="19%" /> 1453 <col width="20%" /> 1454 <col width="10%" /> 1455 <col width="23%" /> 1456 <col width="17%" /> 1457 </colgroup><tbody><tr> 1458 <th>CVE</th> 1459 <th></th> 1460 <th></th> 1461 <th> Google </th> 1462 <th></th> 1463 </tr> 1464 <tr> 1465 <td>CVE-2017-0620</td> 1466 <td>A-35401052<br /> 1467 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=01b2c9a5d728ff6f2f1f28a5d4e927aaeabf56ed"> 1468 QC-CR#1081711</a></td> 1469 <td></td> 1470 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 1471 <td>2017 2 15 </td> 1472 </tr> 1473 </tbody></table> 1474 1475 <h3 id="eop-in-qualcomm-sound-codec-driver">Qualcomm </h3> 1476 1477 <p>Qualcomm </p> 1478 1479 <table> 1480 <colgroup><col width="19%" /> 1481 <col width="20%" /> 1482 <col width="10%" /> 1483 <col width="23%" /> 1484 <col width="17%" /> 1485 </colgroup><tbody><tr> 1486 <th>CVE</th> 1487 <th></th> 1488 <th></th> 1489 <th> Google </th> 1490 <th></th> 1491 </tr> 1492 <tr> 1493 <td>CVE-2016-5862</td> 1494 <td>A-35399803<br /> 1495 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=4199451e83729a3add781eeafaee32994ff65b04"> 1496 QC-CR#1099607</a></td> 1497 <td></td> 1498 <td>PixelPixel XL</td> 1499 <td>2017 2 15 </td> 1500 </tr> 1501 </tbody></table> 1502 1503 <h3 id="eop-in-kernel-voltage-regulator-driver"> </h3> 1504 1505 <p> </p> 1506 1507 <table> 1508 <colgroup><col width="19%" /> 1509 <col width="20%" /> 1510 <col width="10%" /> 1511 <col width="23%" /> 1512 <col width="17%" /> 1513 </colgroup><tbody><tr> 1514 <th>CVE</th> 1515 <th></th> 1516 <th></th> 1517 <th> Google </th> 1518 <th></th> 1519 </tr> 1520 <tr> 1521 <td>CVE-2014-9940</td> 1522 <td>A-35399757<br /> 1523 <a href="https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable.git/commit/?id=60a2362f769cf549dc466134efe71c8bf9fbaaba"> 1524 </a></td> 1525 <td></td> 1526 <td>Nexus 6Nexus 9Pixel CAndroid OneNexus Player</td> 1527 <td>2017 2 15 </td> 1528 </tr> 1529 </tbody></table> 1530 1531 <h3 id="eop-in-qualcomm-camera-driver">Qualcomm </h3> 1532 1533 <p>Qualcomm </p> 1534 1535 <table> 1536 <colgroup><col width="19%" /> 1537 <col width="20%" /> 1538 <col width="10%" /> 1539 <col width="23%" /> 1540 <col width="17%" /> 1541 </colgroup><tbody><tr> 1542 <th>CVE</th> 1543 <th></th> 1544 <th></th> 1545 <th> Google </th> 1546 <th></th> 1547 </tr> 1548 <tr> 1549 <td>CVE-2017-0621</td> 1550 <td>A-35399703<br /> 1551 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.10/commit/?id=9656e2c2b3523af20502bf1e933e35a397f5e82f"> 1552 QC-CR#831322</a></td> 1553 <td></td> 1554 <td>Android One</td> 1555 <td>2017 2 15 </td> 1556 </tr> 1557 </tbody></table> 1558 1559 <h3 id="eop-in-qualcomm-networking-driver">Qualcomm </h3> 1560 1561 <p>Qualcomm </p> 1562 1563 <table> 1564 <colgroup><col width="19%" /> 1565 <col width="20%" /> 1566 <col width="10%" /> 1567 <col width="23%" /> 1568 <col width="17%" /> 1569 </colgroup><tbody><tr> 1570 <th>CVE</th> 1571 <th></th> 1572 <th></th> 1573 <th> Google </th> 1574 <th></th> 1575 </tr> 1576 <tr> 1577 <td>CVE-2016-5868</td> 1578 <td>A-35392791<br /> 1579 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=fbb765a3f813f5cc85ddab21487fd65f24bf6a8c"> 1580 QC-CR#1104431</a></td> 1581 <td></td> 1582 <td>Nexus 5XPixelPixel XL</td> 1583 <td>2017 2 15 </td> 1584 </tr> 1585 </tbody></table> 1586 1587 <h3 id="eop-in-kernel-networking-subsystem"> </h3> 1588 1589 <p> </p> 1590 1591 <table> 1592 <colgroup><col width="19%" /> 1593 <col width="20%" /> 1594 <col width="10%" /> 1595 <col width="23%" /> 1596 <col width="17%" /> 1597 </colgroup><tbody><tr> 1598 <th>CVE</th> 1599 <th></th> 1600 <th></th> 1601 <th> Google </th> 1602 <th></th> 1603 </tr> 1604 <tr> 1605 <td>CVE-2017-7184</td> 1606 <td>A-36565222<br /> 1607 <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=677e806da4d916052585301785d847c3b3e6186a"> 1608 </a> <a href="https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=f843ee6dd019bcece3e74e76ad9df0155655d0df"> 1609 [2]</a></td> 1610 <td></td> 1611 <td>Nexus 5XNexus 6Nexus 6PNexus 9PixelPixel XLAndroid One</td> 1612 <td>2017 5 23 </td> 1613 </tr> 1614 </tbody></table> 1615 1616 <h3 id="eop-in-goodix-touchscreen-driver">Goodix </h3> 1617 1618 <p>Goodix </p> 1619 1620 <table> 1621 <colgroup><col width="19%" /> 1622 <col width="20%" /> 1623 <col width="10%" /> 1624 <col width="23%" /> 1625 <col width="17%" /> 1626 </colgroup><tbody><tr> 1627 <th>CVE</th> 1628 <th></th> 1629 <th></th> 1630 <th> Google </th> 1631 <th></th> 1632 </tr> 1633 <tr> 1634 <td>CVE-2017-0622</td> 1635 <td>A-32749036<br /> 1636 <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=40efa25345003a96db34effbd23ed39530b3ac10"> 1637 QC-CR#1098602</a></td> 1638 <td></td> 1639 <td>Android One</td> 1640 <td>Google </td> 1641 </tr> 1642 </tbody></table> 1643 1644 <h3 id="eop-in-htc-bootloader">HTC </h3> 1645 1646 <p>HTC </p> 1647 1648 <table> 1649 <colgroup><col width="19%" /> 1650 <col width="20%" /> 1651 <col width="10%" /> 1652 <col width="23%" /> 1653 <col width="17%" /> 1654 </colgroup><tbody><tr> 1655 <th>CVE</th> 1656 <th></th> 1657 <th></th> 1658 <th> Google </th> 1659 <th></th> 1660 </tr> 1661 <tr> 1662 <td>CVE-2017-0623</td> 1663 <td>A-32512358*<br /> 1664 </td> 1665 <td></td> 1666 <td>PixelPixel XL</td> 1667 <td>Google </td> 1668 </tr> 1669 </tbody></table> 1670 1671 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 1672 1673 <h3 id="id-in-qualcomm-wi-fi-driver">Qualcomm Wi-Fi </h3> 1674 1675 <p>Qualcomm Wi-Fi </p> 1676 1677 <table> 1678 <colgroup><col width="19%" /> 1679 <col width="20%" /> 1680 <col width="10%" /> 1681 <col width="23%" /> 1682 <col width="17%" /> 1683 </colgroup><tbody><tr> 1684 <th>CVE</th> 1685 <th></th> 1686 <th></th> 1687 <th> Google </th> 1688 <th></th> 1689 </tr> 1690 <tr> 1691 <td>CVE-2017-0624</td> 1692 <td>A-34327795*<br /> 1693 QC-CR#2005832</td> 1694 <td></td> 1695 <td>Nexus 5XPixelPixel XL</td> 1696 <td>2017 1 16 </td> 1697 </tr> 1698 </tbody></table> 1699 1700 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 1701 1702 <h3 id="id-in-mediatek-command-queue-driver">MediaTek </h3> 1703 1704 <p>MediaTek </p> 1705 1706 <table> 1707 <colgroup><col width="19%" /> 1708 <col width="20%" /> 1709 <col width="10%" /> 1710 <col width="23%" /> 1711 <col width="17%" /> 1712 </colgroup><tbody><tr> 1713 <th>CVE</th> 1714 <th></th> 1715 <th></th> 1716 <th> Google </th> 1717 <th></th> 1718 </tr> 1719 <tr> 1720 <td>CVE-2017-0625</td> 1721 <td>A-35142799*<br /> 1722 M-ALPS03161531</td> 1723 <td></td> 1724 <td>**</td> 1725 <td>2017 2 8 </td> 1726 </tr> 1727 </tbody></table> 1728 1729 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 1730 1731 <p>** Android 7.1.1 Google </p> 1732 1733 <h3 id="id-in-qualcomm-crypto-engine-driver">Qualcomm crypto </h3> 1734 1735 <p>Qualcomm crypto </p> 1736 1737 <table> 1738 <colgroup><col width="19%" /> 1739 <col width="20%" /> 1740 <col width="10%" /> 1741 <col width="23%" /> 1742 <col width="17%" /> 1743 </colgroup><tbody><tr> 1744 <th>CVE</th> 1745 <th></th> 1746 <th></th> 1747 <th> Google </th> 1748 <th></th> 1749 </tr> 1750 <tr> 1751 <td>CVE-2017-0626</td> 1752 <td>A-35393124<br /> 1753 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=64551bccab9b5b933757f6256b58f9ca0544f004"> 1754 QC-CR#1088050</a></td> 1755 <td></td> 1756 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 1757 <td>2017 2 15 </td> 1758 </tr> 1759 </tbody></table> 1760 1761 <h3 id="dos-in-qualcomm-wi-fi-driver">Qualcomm Wi-Fi </h3> 1762 1763 <p>Qualcomm Wi-Fi Wi-Fi </p> 1764 1765 <table> 1766 <colgroup><col width="19%" /> 1767 <col width="20%" /> 1768 <col width="10%" /> 1769 <col width="23%" /> 1770 <col width="17%" /> 1771 </colgroup><tbody><tr> 1772 <th>CVE</th> 1773 <th></th> 1774 <th></th> 1775 <th> Google </th> 1776 <th></th> 1777 </tr> 1778 <tr> 1779 <td>CVE-2016-10292</td> 1780 <td>A-34514463*<br /> 1781 QC-CR#1065466</td> 1782 <td></td> 1783 <td>Nexus 5XPixelPixel XL</td> 1784 <td>2016 12 16 </td> 1785 </tr> 1786 </tbody></table> 1787 1788 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 1789 1790 <h3 id="id-in-kernel-uvc-driver"> UVC </h3> 1791 1792 <p> UVC </p> 1793 1794 <table> 1795 <colgroup><col width="19%" /> 1796 <col width="20%" /> 1797 <col width="10%" /> 1798 <col width="23%" /> 1799 <col width="17%" /> 1800 </colgroup><tbody><tr> 1801 <th>CVE</th> 1802 <th></th> 1803 <th></th> 1804 <th> Google </th> 1805 <th></th> 1806 </tr> 1807 <tr> 1808 <td>CVE-2017-0627</td> 1809 <td>A-33300353*<br /> 1810 </td> 1811 <td></td> 1812 <td>Nexus 5XNexus 6PNexus 9Pixel CNexus Player</td> 1813 <td>2016 12 2 </td> 1814 </tr> 1815 </tbody></table> 1816 1817 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 1818 1819 <h3 id="id-in-qualcomm-video-driver">Qualcomm </h3> 1820 1821 <p> 1822 Qualcomm </p> 1823 1824 <table> 1825 <colgroup><col width="19%" /> 1826 <col width="20%" /> 1827 <col width="10%" /> 1828 <col width="23%" /> 1829 <col width="17%" /> 1830 </colgroup><tbody><tr> 1831 <th>CVE</th> 1832 <th></th> 1833 <th></th> 1834 <th> Google </th> 1835 <th></th> 1836 </tr> 1837 <tr> 1838 <td>CVE-2016-10293</td> 1839 <td>A-33352393<br /> 1840 <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=2469d5374745a2228f774adbca6fb95a79b9047f"> 1841 QC-CR#1101943</a></td> 1842 <td></td> 1843 <td>Nexus 5XNexus 6PAndroid One</td> 1844 <td>2016 12 4 </td> 1845 </tr> 1846 </tbody></table> 1847 1848 <h3 id="id-in-qualcomm-power-driver-(device-specific)">Qualcomm </h3> 1849 1850 <p>Qualcomm </p> 1851 1852 <table> 1853 <colgroup><col width="19%" /> 1854 <col width="20%" /> 1855 <col width="10%" /> 1856 <col width="23%" /> 1857 <col width="17%" /> 1858 </colgroup><tbody><tr> 1859 <th>CVE</th> 1860 <th></th> 1861 <th></th> 1862 <th> Google </th> 1863 <th></th> 1864 </tr> 1865 <tr> 1866 <td>CVE-2016-10294</td> 1867 <td>A-33621829<br /> 1868 <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=9e9bc51ffb8a298f0be5befe346762cdb6e1d49c"> 1869 QC-CR#1105481</a></td> 1870 <td></td> 1871 <td>Nexus 5XNexus 6PPixelPixel XL</td> 1872 <td>2016 12 14 </td> 1873 </tr> 1874 </tbody></table> 1875 1876 <h3 id="id-in-qualcomm-led-driver">Qualcomm LED </h3> 1877 1878 <p>Qualcomm LED </p> 1879 1880 <table> 1881 <colgroup><col width="19%" /> 1882 <col width="20%" /> 1883 <col width="10%" /> 1884 <col width="23%" /> 1885 <col width="17%" /> 1886 </colgroup><tbody><tr> 1887 <th>CVE</th> 1888 <th></th> 1889 <th></th> 1890 <th> Google </th> 1891 <th></th> 1892 </tr> 1893 <tr> 1894 <td>CVE-2016-10295</td> 1895 <td>A-33781694<br /> 1896 <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=f11ae3df500bc2a093ddffee6ea40da859de0fa9"> 1897 QC-CR#1109326</a></td> 1898 <td></td> 1899 <td>PixelPixel XL</td> 1900 <td>2016 12 20 </td> 1901 </tr> 1902 </tbody></table> 1903 1904 <h3 id="id-in-qualcomm-shared-memory-driver">Qualcomm </h3> 1905 1906 <p>Qualcomm </p> 1907 1908 <table> 1909 <colgroup><col width="19%" /> 1910 <col width="20%" /> 1911 <col width="10%" /> 1912 <col width="23%" /> 1913 <col width="17%" /> 1914 </colgroup><tbody><tr> 1915 <th>CVE</th> 1916 <th></th> 1917 <th></th> 1918 <th> Google </th> 1919 <th></th> 1920 </tr> 1921 <tr> 1922 <td>CVE-2016-10296</td> 1923 <td>A-33845464<br /> 1924 <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=a5e46d8635a2e28463b365aacdeab6750abd0d49"> 1925 QC-CR#1109782</a></td> 1926 <td></td> 1927 <td>Nexus 5XNexus 6PPixelPixel XLAndroid One</td> 1928 <td>2016 12 22 </td> 1929 </tr> 1930 </tbody></table> 1931 1932 <h3 id="id-in-qualcomm-camera-driver">Qualcomm </h3> 1933 1934 <p>Qualcomm </p> 1935 1936 <table> 1937 <colgroup><col width="19%" /> 1938 <col width="20%" /> 1939 <col width="10%" /> 1940 <col width="23%" /> 1941 <col width="17%" /> 1942 </colgroup><tbody><tr> 1943 <th>CVE</th> 1944 <th></th> 1945 <th></th> 1946 <th> Google </th> 1947 <th></th> 1948 </tr> 1949 <tr> 1950 <td>CVE-2017-0628</td> 1951 <td>A-34230377<br /> 1952 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=012e37bf91490c5b59ba2ab68a4d214b632b613f"> 1953 QC-CR#1086833</a></td> 1954 <td></td> 1955 <td>Nexus 5XNexus 6PixelPixel XL</td> 1956 <td>2017 1 10 </td> 1957 </tr> 1958 <tr> 1959 <td>CVE-2017-0629</td> 1960 <td>A-35214296<br /> 1961 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=012e37bf91490c5b59ba2ab68a4d214b632b613f"> 1962 QC-CR#1086833</a></td> 1963 <td></td> 1964 <td>Nexus 5XNexus 6PixelPixel XL</td> 1965 <td>2017 2 8 </td> 1966 </tr> 1967 </tbody></table> 1968 1969 <h3 id="id-in-kernel-trace-subsystem"> </h3> 1970 1971 <p> </p> 1972 1973 <table> 1974 <colgroup><col width="19%" /> 1975 <col width="20%" /> 1976 <col width="10%" /> 1977 <col width="23%" /> 1978 <col width="17%" /> 1979 </colgroup><tbody><tr> 1980 <th>CVE</th> 1981 <th></th> 1982 <th></th> 1983 <th> Google </th> 1984 <th></th> 1985 </tr> 1986 <tr> 1987 <td>CVE-2017-0630</td> 1988 <td>A-34277115*<br /> 1989 </td> 1990 <td></td> 1991 <td>Nexus 5XNexus 6Nexus 6PNexus 9PixelPixel XLPixel CAndroid OneNexus Player</td> 1992 <td>2017 1 11 </td> 1993 </tr> 1994 </tbody></table> 1995 1996 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 1997 1998 <h3 id="id-in-qualcomm-sound-codec-driver">Qualcomm </h3> 1999 2000 <p>Qualcomm </p> 2001 2002 <table> 2003 <colgroup><col width="19%" /> 2004 <col width="20%" /> 2005 <col width="10%" /> 2006 <col width="23%" /> 2007 <col width="17%" /> 2008 </colgroup><tbody><tr> 2009 <th>CVE</th> 2010 <th></th> 2011 <th></th> 2012 <th> Google </th> 2013 <th></th> 2014 </tr> 2015 <tr> 2016 <td>CVE-2016-5858</td> 2017 <td>A-35400153<br /> 2018 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=3154eb1d263b9c3eab2c9fa8ebe498390bf5d711"> 2019 QC-CR#1096799</a> <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=afc5bea71bc8f251dad1104568383019f4923af6"> 2020 [2]</a></td> 2021 <td></td> 2022 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 2023 <td>2017 2 15 </td> 2024 </tr> 2025 </tbody></table> 2026 2027 <h3 id="id-in-qualcomm-camera-driver-2">Qualcomm </h3> 2028 2029 <p>Qualcomm </p> 2030 2031 <table> 2032 <colgroup><col width="19%" /> 2033 <col width="20%" /> 2034 <col width="10%" /> 2035 <col width="23%" /> 2036 <col width="17%" /> 2037 </colgroup><tbody><tr> 2038 <th>CVE</th> 2039 <th></th> 2040 <th></th> 2041 <th> Google </th> 2042 <th></th> 2043 </tr> 2044 <tr> 2045 <td>CVE-2017-0631</td> 2046 <td>A-35399756<br /> 2047 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=8236d6ebc7e26361ca7078cbeba01509f10941d8"> 2048 QC-CR#1093232</a></td> 2049 <td></td> 2050 <td>Nexus 5XNexus 6PPixelPixel XLAndroid One</td> 2051 <td>2017 2 15 </td> 2052 </tr> 2053 </tbody></table> 2054 2055 <h3 id="id-in-qualcomm-sound-driver">Qualcomm </h3> 2056 2057 <p>Qualcomm </p> 2058 2059 <table> 2060 <colgroup><col width="19%" /> 2061 <col width="20%" /> 2062 <col width="10%" /> 2063 <col width="23%" /> 2064 <col width="17%" /> 2065 </colgroup><tbody><tr> 2066 <th>CVE</th> 2067 <th></th> 2068 <th></th> 2069 <th> Google </th> 2070 <th></th> 2071 </tr> 2072 <tr> 2073 <td>CVE-2016-5347</td> 2074 <td>A-35394329<br /> 2075 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=f14390f13e62460fc6b05fc0acde0e825374fdb6"> 2076 QC-CR#1100878</a></td> 2077 <td></td> 2078 <td>Nexus 5XNexus 6Nexus 6PPixelPixel XLAndroid One</td> 2079 <td>2017 2 15 </td> 2080 </tr> 2081 </tbody></table> 2082 2083 <h3 id="id-in-qualcomm-spcom-driver">Qualcomm SPCom </h3> 2084 2085 <p>Qualcomm SPCom </p> 2086 2087 <table> 2088 <colgroup><col width="19%" /> 2089 <col width="20%" /> 2090 <col width="10%" /> 2091 <col width="23%" /> 2092 <col width="17%" /> 2093 </colgroup><tbody><tr> 2094 <th>CVE</th> 2095 <th></th> 2096 <th></th> 2097 <th> Google </th> 2098 <th></th> 2099 </tr> 2100 <tr> 2101 <td>CVE-2016-5854</td> 2102 <td>A-35392792<br /> 2103 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=28d23d4d7999f683b27b6e0c489635265b67a4c9"> 2104 QC-CR#1092683</a></td> 2105 <td></td> 2106 <td>*</td> 2107 <td>2017 2 15 </td> 2108 </tr> 2109 <tr> 2110 <td>CVE-2016-5855</td> 2111 <td>A-35393081<br /> 2112 <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=a5edb54e93ba85719091fe2bc426d75fa7059834"> 2113 QC-CR#1094143</a></td> 2114 <td></td> 2115 <td>*</td> 2116 <td>2017 2 15 </td> 2117 </tr> 2118 </tbody></table> 2119 2120 <p>* Android 7.1.1 Google </p> 2121 2122 <h3 id="id-in-qualcomm-sound-codec-driver-2">Qualcomm </h3> 2123 2124 <p>Qualcomm </p> 2125 2126 <table> 2127 <colgroup><col width="19%" /> 2128 <col width="20%" /> 2129 <col width="10%" /> 2130 <col width="23%" /> 2131 <col width="17%" /> 2132 </colgroup><tbody><tr> 2133 <th>CVE</th> 2134 <th></th> 2135 <th></th> 2136 <th> Google </th> 2137 <th></th> 2138 </tr> 2139 <tr> 2140 <td>CVE-2017-0632</td> 2141 <td>A-35392586<br /> 2142 <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.10/commit/?id=970d6933e53c1f7ca8c8b67f49147b18505c3b8f"> 2143 QC-CR#832915</a></td> 2144 <td></td> 2145 <td>Android One</td> 2146 <td>2017 2 15 </td> 2147 </tr> 2148 </tbody></table> 2149 2150 <h3 id="id-in-broadcom-wi-fi-driver">Broadcom Wi-Fi </h3> 2151 2152 <p>Broadcom Wi-Fi </p> 2153 2154 <table> 2155 <colgroup><col width="19%" /> 2156 <col width="20%" /> 2157 <col width="10%" /> 2158 <col width="23%" /> 2159 <col width="17%" /> 2160 </colgroup><tbody><tr> 2161 <th>CVE</th> 2162 <th></th> 2163 <th></th> 2164 <th> Google </th> 2165 <th></th> 2166 </tr> 2167 <tr> 2168 <td>CVE-2017-0633</td> 2169 <td>A-36000515*<br /> 2170 B-RB#117131</td> 2171 <td></td> 2172 <td>Nexus 6Nexus 6PNexus 9Pixel CNexus Player</td> 2173 <td>2017 2 23 </td> 2174 </tr> 2175 </tbody></table> 2176 2177 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 2178 2179 <h3 id="id-in-synaptics-touchscreen-driver">Synaptics </h3> 2180 2181 <p>Synaptics </p> 2182 2183 <table> 2184 <colgroup><col width="19%" /> 2185 <col width="20%" /> 2186 <col width="10%" /> 2187 <col width="23%" /> 2188 <col width="17%" /> 2189 </colgroup><tbody><tr> 2190 <th>CVE</th> 2191 <th></th> 2192 <th></th> 2193 <th> Google </th> 2194 <th></th> 2195 </tr> 2196 <tr> 2197 <td>CVE-2017-0634</td> 2198 <td>A-32511682*<br /> 2199 </td> 2200 <td></td> 2201 <td>PixelPixel XL</td> 2202 <td>Google </td> 2203 </tr> 2204 </tbody></table> 2205 2206 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 2207 2208 <h3 id="vulnerabilities-in-qualcomm-components-2">Qualcomm </h3> 2209 2210 <p>Qualcomm 20142016 Qualcomm AMSS Android Android </p> 2211 2212 <table> 2213 <colgroup><col width="19%" /> 2214 <col width="20%" /> 2215 <col width="10%" /> 2216 <col width="23%" /> 2217 <col width="17%" /> 2218 </colgroup><tbody><tr> 2219 <th>CVE</th> 2220 <th></th> 2221 <th></th> 2222 <th> Google </th> 2223 <th></th> 2224 </tr> 2225 <tr> 2226 <td>CVE-2014-9923</td> 2227 <td>A-35434045**<br /> 2228 QC-CR#403910</td> 2229 <td></td> 2230 <td>***</td> 2231 <td>Qualcomm </td> 2232 </tr> 2233 <tr> 2234 <td>CVE-2014-9924</td> 2235 <td>A-35434631**<br /> 2236 QC-CR#596102</td> 2237 <td></td> 2238 <td>***</td> 2239 <td>Qualcomm </td> 2240 </tr> 2241 <tr> 2242 <td>CVE-2014-9925</td> 2243 <td>A-35444657**<br /> 2244 QC-CR#638130</td> 2245 <td></td> 2246 <td>***</td> 2247 <td>Qualcomm </td> 2248 </tr> 2249 <tr> 2250 <td>CVE-2014-9926</td> 2251 <td>A-35433784**<br /> 2252 QC-CR#631527</td> 2253 <td></td> 2254 <td>***</td> 2255 <td>Qualcomm </td> 2256 </tr> 2257 <tr> 2258 <td>CVE-2014-9927</td> 2259 <td>A-35433785**<br /> 2260 QC-CR#661111</td> 2261 <td></td> 2262 <td>***</td> 2263 <td>Qualcomm </td> 2264 </tr> 2265 <tr> 2266 <td>CVE-2014-9928</td> 2267 <td>A-35438623**<br /> 2268 QC-CR#696972</td> 2269 <td></td> 2270 <td>***</td> 2271 <td>Qualcomm </td> 2272 </tr> 2273 <tr> 2274 <td>CVE-2014-9929</td> 2275 <td>A-35443954**<br /> 2276 QC-CR#644783</td> 2277 <td></td> 2278 <td>***</td> 2279 <td>Qualcomm </td> 2280 </tr> 2281 <tr> 2282 <td>CVE-2014-9930</td> 2283 <td>A-35432946**<br /> 2284 QC-CR#634637</td> 2285 <td></td> 2286 <td>***</td> 2287 <td>Qualcomm </td> 2288 </tr> 2289 <tr> 2290 <td>CVE-2015-9005</td> 2291 <td>A-36393500**<br /> 2292 QC-CR#741548</td> 2293 <td></td> 2294 <td>***</td> 2295 <td>Qualcomm </td> 2296 </tr> 2297 <tr> 2298 <td>CVE-2015-9006</td> 2299 <td>A-36393450**<br /> 2300 QC-CR#750559</td> 2301 <td></td> 2302 <td>***</td> 2303 <td>Qualcomm </td> 2304 </tr> 2305 <tr> 2306 <td>CVE-2015-9007</td> 2307 <td>A-36393700**<br /> 2308 QC-CR#807173</td> 2309 <td></td> 2310 <td>***</td> 2311 <td>Qualcomm </td> 2312 </tr> 2313 <tr> 2314 <td>CVE-2016-10297</td> 2315 <td>A-36393451**<br /> 2316 QC-CR#1061123</td> 2317 <td></td> 2318 <td>***</td> 2319 <td>Qualcomm </td> 2320 </tr> 2321 <tr> 2322 <td>CVE-2014-9941</td> 2323 <td>A-36385125**<br /> 2324 QC-CR#509915</td> 2325 <td></td> 2326 <td>***</td> 2327 <td>Qualcomm </td> 2328 </tr> 2329 <tr> 2330 <td>CVE-2014-9942</td> 2331 <td>A-36385319**<br /> 2332 QC-CR#533283</td> 2333 <td></td> 2334 <td>***</td> 2335 <td>Qualcomm </td> 2336 </tr> 2337 <tr> 2338 <td>CVE-2014-9943</td> 2339 <td>A-36385219**<br /> 2340 QC-CR#546527</td> 2341 <td></td> 2342 <td>***</td> 2343 <td>Qualcomm </td> 2344 </tr> 2345 <tr> 2346 <td>CVE-2014-9944</td> 2347 <td>A-36384534**<br /> 2348 QC-CR#613175</td> 2349 <td></td> 2350 <td>***</td> 2351 <td>Qualcomm </td> 2352 </tr> 2353 <tr> 2354 <td>CVE-2014-9945</td> 2355 <td>A-36386912**<br /> 2356 QC-CR#623452</td> 2357 <td></td> 2358 <td>***</td> 2359 <td>Qualcomm </td> 2360 </tr> 2361 <tr> 2362 <td>CVE-2014-9946</td> 2363 <td>A-36385281**<br /> 2364 QC-CR#520149</td> 2365 <td></td> 2366 <td>***</td> 2367 <td>Qualcomm </td> 2368 </tr> 2369 <tr> 2370 <td>CVE-2014-9947</td> 2371 <td>A-36392400**<br /> 2372 QC-CR#650540</td> 2373 <td></td> 2374 <td>***</td> 2375 <td>Qualcomm </td> 2376 </tr> 2377 <tr> 2378 <td>CVE-2014-9948</td> 2379 <td>A-36385126**<br /> 2380 QC-CR#650500</td> 2381 <td></td> 2382 <td>***</td> 2383 <td>Qualcomm </td> 2384 </tr> 2385 <tr> 2386 <td>CVE-2014-9949</td> 2387 <td>A-36390608**<br /> 2388 QC-CR#652426</td> 2389 <td></td> 2390 <td>***</td> 2391 <td>Qualcomm </td> 2392 </tr> 2393 <tr> 2394 <td>CVE-2014-9950</td> 2395 <td>A-36385321**<br /> 2396 QC-CR#655530</td> 2397 <td></td> 2398 <td>***</td> 2399 <td>Qualcomm </td> 2400 </tr> 2401 <tr> 2402 <td>CVE-2014-9951</td> 2403 <td>A-36389161**<br /> 2404 QC-CR#525043</td> 2405 <td></td> 2406 <td>***</td> 2407 <td>Qualcomm </td> 2408 </tr> 2409 <tr> 2410 <td>CVE-2014-9952</td> 2411 <td>A-36387019**<br /> 2412 QC-CR#674836</td> 2413 <td></td> 2414 <td>***</td> 2415 <td>Qualcomm </td> 2416 </tr> 2417 </tbody></table> 2418 2419 <p>* </p> 2420 2421 <p>* <a href="https://developers.google.com/android/nexus/drivers">Google </a> Nexus </p> 2422 2423 <p>*** Android 7.1.1 Google </p> 2424 2425 <h2 id="common-questions-and-answers"></h2> 2426 <p></p> 2427 2428 <p><strong>1. 2429 </strong></p> 2430 2431 <p> <a href="https://support.google.com/pixelphone/answer/4457705#pixel_phones&nexus_devices">Pixel Nexus </a></p> 2432 2433 <ul> 2434 <li> 2017-05-01 2017-05-01 </li> 2435 <li> 2017-05-05 2017-05-05 2436 </li> 2437 </ul> 2438 2439 <p></p> 2440 <ul> 2441 <li>[ro.build.version.security_patch]:[2017-05-01]</li> 2442 <li>[ro.build.version.security_patch]:[2017-05-05]</li> 2443 </ul> 2444 2445 <p><strong>2. 2 </strong></p> 2446 2447 <p>2 Android Android Android </p> 2448 <ul> 2449 <li>2017 5 1 </li> 2450 <li>2017 5 5 </li> 2451 </ul> 2452 2453 <p> 1 </p> 2454 2455 <p><strong>3. Google </strong></p> 2456 2457 <p><a href="#2017-05-01-details">2017-05-01</a> <a href="#2017-05-05-details">2017-05-05</a> Google Google <em></em></p> 2458 <ul> 2459 <li><strong> Google </strong>: Pixel Google <em></em><a href="https://support.google.com/pixelphone/answer/4457705#pixel_phones&nexus_devices"></a>Nexus 5XNexus 6Nexus 6PNexus 9Android OneNexus PlayerPixel CPixelPixel XL</li> 2460 <li><strong> Google </strong>: Google Google Google <em></em></li> 2461 <li><strong> Google </strong>: Android 7.0 Google Google <em></em></li> 2462 </ul> 2463 <p><strong>4. </strong></p> 2464 2465 <p><em></em></p> 2466 2467 <table> 2468 <tbody><tr> 2469 <th></th> 2470 <th></th> 2471 </tr> 2472 <tr> 2473 <td>A-</td> 2474 <td>Android ID</td> 2475 </tr> 2476 <tr> 2477 <td>QC-</td> 2478 <td>Qualcomm </td> 2479 </tr> 2480 <tr> 2481 <td>M-</td> 2482 <td>MediaTek </td> 2483 </tr> 2484 <tr> 2485 <td>N-</td> 2486 <td>NVIDIA </td> 2487 </tr> 2488 <tr> 2489 <td>B-</td> 2490 <td>Broadcom </td> 2491 </tr> 2492 </tbody></table> 2493 <h2 id="revisions"></h2> 2494 <ul> 2495 <li>2017 5 1 : </li> 2496 <li>2017 5 2 : AOSP </li> 2497 </ul> 2498 2499 </body></html>