Home | History | Annotate | Download | only in bulletin
      1 <html devsite><head>
      2     <title>Android    2017 6</title>
      3     <meta name="project_path" value="/_project.yaml"/>
      4     <meta name="book_path" value="/_book.yaml"/>
      5   </head>
      6   <body>
      7   <!--
      8       Copyright 2017 The Android Open Source Project
      9 
     10       Licensed under the Apache License, Version 2.0 (the "License");
     11       you may not use this file except in compliance with the License.
     12       You may obtain a copy of the License at
     13 
     14           http://www.apache.org/licenses/LICENSE-2.0
     15 
     16       Unless required by applicable law or agreed to in writing, software
     17       distributed under the License is distributed on an "AS IS" BASIS,
     18       WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
     19       See the License for the specific language governing permissions and
     20       limitations under the License.
     21   -->
     22 <p><em>2017 6 5  | 2017 6 7 </em></p>
     23 
     24 <p>Android   Android     
     25  .    2017 6 5
     26      . <a href="https://support.google.com/pixelphone/answer/4457705#pixel_phones&nexus_devices">Pixel  Nexus  </a>
     27        .</p>
     28 
     29 <p>     
     30     .       
     31 Android  (AOSP)      . 
     32  AOSP     .</p>
     33 
     34 <p>         ,
     35            
     36     . <a href="/security/overview/updates-resources.html#severity"> </a>
     37         
     38          
     39  .</p>
     40 
     41 <p>        
     42  . Android   
     43 <a href="/security/enhancements/index.html">Android   </a> 
     44 <a href="https://www.android.com/play-protect">Google Play Protect</a>  
     45  <a href="#mitigations">Android  Google Play Protect </a>
     46  .</p>
     47 
     48 <p>       .</p>
     49 
     50 <p class="note"><strong>:</strong>   (OTA)   
     51 Google    <a href="#google-device-updates">Google  </a>  .</p>
     52 
     53 <h2 id="announcements"></h2>
     54 <ul>
     55   <li>     
     56   .     
     57          
     58     , Google  
     59   <a href="#google-device-updates"> </a> .</li>
     60   <li>  Android   Android   
     61           
     62          .   <a href="#common-questions-and-answers">   </a>
     63   .
     64     <ul>
     65       <li><strong>2017-06-01</strong>:     .     
     66       2017-06-01        
     67         .</li>
     68       <li><strong>2017-06-05</strong>:     .     
     69       2017-06-01 2017-06-05     
     70          
     71        .</li>
     72     </ul>
     73   </li>
     74 </ul>
     75 
     76 <h2 id="mitigations">Android  Google Play Protect </h2>
     77 <p> <a href="https://www.android.com/play-protect">Google Play Protect</a>  <a href="/security/enhancements/index.html">Android  </a>
     78       
     79 .
     80    Android  
     81   .</p>
     82 <ul>
     83   <li>Android      Android  
     84     .      Android
     85     .</li>
     86   <li>Android  <a href="https://www.android.com/play-protect">Google Play Protect</a> 
     87     
     88   <a href="/security/reports/Google_Android_Security_PHA_classifications.pdf">  </a> 
     89     . Google Play Protect <a href="http://www.android.com/gms">Google  </a> 
     90       
     91   Google Play       .</li>
     92 </ul>
     93 
     94 <h2 id="2017-06-01-details">2017-06-01    </h2>
     95 <p>  2017-06-01   
     96        .   
     97    .    
     98 CVE,  , <a href="#vulnerability-type"> </a>, <a href="/security/overview/updates-resources.html#severity"></a>,  AOSP ( )
     99   .   AOSP   
    100      ID . 
    101          ID  
    102  .</p>
    103 
    104 <h3 id="bluetooth"></h3>
    105 <p>        
    106       .</p>
    107 
    108 <table>
    109   <colgroup><col width="17%" />
    110   <col width="19%" />
    111   <col width="9%" />
    112   <col width="14%" />
    113   <col width="39%" />
    114   </colgroup><tbody><tr>
    115    <th>CVE</th>
    116    <th></th>
    117    <th></th>
    118    <th></th>
    119    <th> AOSP </th>
    120   </tr>
    121   <tr>
    122    <td>CVE-2017-0639</td>
    123    <td><a href="https://android.googlesource.com/platform/packages/apps/Bluetooth/+/f196061addcc56878078e5684f2029ddbf7055ff">A-35310991</a></td>
    124    <td>ID</td>
    125    <td></td>
    126    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    127   </tr>
    128   <tr>
    129    <td>CVE-2017-0645</td>
    130    <td><a href="https://android.googlesource.com/platform/packages/apps/Bluetooth/+/14b7d7e1537af60b7bca6c7b9e55df0dc7c6bf41">A-35385327</a></td>
    131    <td>EoP</td>
    132    <td></td>
    133    <td>6.0.1, 7.0, 7.1.1, 7.1.2</td>
    134   </tr>
    135   <tr>
    136    <td>CVE-2017-0646</td>
    137    <td><a href="https://android.googlesource.com/platform/system/bt/+/2bcdf8ec7db12c5651c004601901f1fc25153f2c">A-33899337</a></td>
    138    <td>ID</td>
    139    <td></td>
    140    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    141   </tr>
    142 </tbody></table>
    143 <h3 id="libraries"></h3>
    144 <p>           
    145        
    146   .</p>
    147 
    148 <table>
    149   <colgroup><col width="17%" />
    150   <col width="19%" />
    151   <col width="9%" />
    152   <col width="14%" />
    153   <col width="39%" />
    154   </colgroup><tbody><tr>
    155    <th>CVE</th>
    156    <th></th>
    157    <th></th>
    158    <th></th>
    159    <th> AOSP </th>
    160   </tr>
    161   <tr>
    162    <td>CVE-2015-8871</td>
    163    <td>A-35443562<a href="#asterisk">*</a></td>
    164    <td>RCE</td>
    165    <td></td>
    166    <td>5.0.2, 5.1.1, 6.0, 6.0.1</td>
    167   </tr>
    168   <tr>
    169    <td>CVE-2016-8332</td>
    170    <td>A-37761553<a href="#asterisk">*</a></td>
    171    <td>RCE</td>
    172    <td></td>
    173    <td>5.0.2, 5.1.1, 6.0, 6.0.1</td>
    174   </tr>
    175   <tr>
    176    <td>CVE-2016-5131</td>
    177    <td><a href="https://android.googlesource.com/platform/external/libxml2/+/0eff71008becb7f2c2b4509708da4b79985948bb">A-36554209</a></td>
    178    <td>RCE</td>
    179    <td></td>
    180    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    181   </tr>
    182   <tr>
    183    <td>CVE-2016-4658</td>
    184    <td><a href="https://android.googlesource.com/platform/external/libxml2/+/8ea80f29ea5fdf383ee3ae59ce35e55421a339f8">A-36554207</a></td>
    185    <td>RCE</td>
    186    <td></td>
    187    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    188   </tr>
    189   <tr>
    190    <td>CVE-2017-0663</td>
    191    <td><a href="https://android.googlesource.com/platform/external/libxml2/+/521b88fbb6d18312923f0df653d045384b500ffc">A-37104170</a></td>
    192    <td>RCE</td>
    193    <td></td>
    194    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    195   </tr>
    196   <tr>
    197    <td>CVE-2017-7376</td>
    198    <td><a href="https://android.googlesource.com/platform/external/libxml2/+/51e0cb2e5ec18eaf6fb331bc573ff27b743898f4">A-36555370</a></td>
    199    <td>RCE</td>
    200    <td></td>
    201    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    202   </tr>
    203   <tr>
    204    <td>CVE-2017-5056</td>
    205    <td><a href="https://android.googlesource.com/platform/external/libxml2/+/3f571b1bb85cf56903f06bab3a820182115c5541">A-36809819</a></td>
    206    <td>RCE</td>
    207    <td></td>
    208    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    209   </tr>
    210   <tr>
    211    <td>CVE-2017-7375</td>
    212    <td><a href="https://android.googlesource.com/platform/external/libxml2/+/308396a55280f69ad4112d4f9892f4cbeff042aa">A-36556310</a></td>
    213    <td>RCE</td>
    214    <td></td>
    215    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    216   </tr>
    217   <tr>
    218    <td>CVE-2017-0647</td>
    219    <td><a href="https://android.googlesource.com/platform/system/core/+/3d6a43155c702bce0e7e2a93a67247b5ce3946a5">A-36392138</a></td>
    220    <td>ID</td>
    221    <td></td>
    222    <td>5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    223   </tr>
    224   <tr>
    225    <td>CVE-2016-1839</td>
    226    <td><a href="https://android.googlesource.com/platform/external/libxml2/+/ff20cd797822dba8569ee518c44e6864d6b4ebfa">A-36553781</a></td>
    227    <td>DoS</td>
    228    <td></td>
    229    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    230   </tr>
    231 </tbody></table>
    232 <h3 id="media-framework"> </h3>
    233 <p>         
    234            
    235 .</p>
    236 
    237 <table>
    238   <colgroup><col width="17%" />
    239   <col width="19%" />
    240   <col width="9%" />
    241   <col width="14%" />
    242   <col width="39%" />
    243   </colgroup><tbody><tr>
    244    <th>CVE</th>
    245    <th></th>
    246    <th></th>
    247    <th></th>
    248    <th> AOSP </th>
    249   </tr>
    250   <tr>
    251    <td>CVE-2017-0637</td>
    252    <td><a href="https://android.googlesource.com/platform/external/libhevc/+/ebaa71da6362c497310377df509651974401d258">A-34064500</a></td>
    253    <td>RCE</td>
    254    <td></td>
    255    <td>5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    256   </tr>
    257   <tr>
    258    <td>CVE-2017-0391</td>
    259    <td><a href="https://android.googlesource.com/platform/external/libhevc/+/14bc1678a80af5be7401cf750ab762ae8c75cc5a">A-32322258</a></td>
    260    <td>DoS</td>
    261    <td></td>
    262    <td>5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    263   </tr>
    264   <tr>
    265    <td>CVE-2017-0640</td>
    266    <td>A-33129467<a href="#asterisk">*</a></td>
    267    <td>DoS</td>
    268    <td></td>
    269    <td>6.0, 6.0.1, 7.0, 7.1.1</td>
    270   </tr>
    271   <tr>
    272    <td>CVE-2017-0641</td>
    273    <td><a href="https://android.googlesource.com/platform/external/libvpx/+/698796fc930baecf5c3fdebef17e73d5d9a58bcb">A-34360591</a></td>
    274    <td>DoS</td>
    275    <td></td>
    276    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    277   </tr>
    278   <tr>
    279    <td>CVE-2017-0642</td>
    280    <td><a href="https://android.googlesource.com/platform/external/libhevc/+/913d9e8d93d6b81bb8eac3fc2c1426651f5b259d">A-34819017</a></td>
    281    <td>DoS</td>
    282    <td></td>
    283    <td>5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2</td>
    284   </tr>
    285   <tr>
    286    <td>CVE-2017-0643</td>
    287    <td>A-35645051<a href="#asterisk">*</a></td>
    288    <td>DoS</td>
    289    <td></td>
    290    <td>5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1</td>
    291   </tr>
    292   <tr>
    293    <td>CVE-2017-0644</td>
    294    <td>A-35472997<a href="#asterisk">*</a></td>
    295    <td>DoS</td>
    296    <td></td>
    297    <td>4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1</td>
    298   </tr>
    299 </tbody></table>
    300 <h3 id="system-ui"> UI</h3>
    301 <p>          
    302          
    303 .</p>
    304 
    305 <table>
    306   <colgroup><col width="17%" />
    307   <col width="19%" />
    308   <col width="9%" />
    309   <col width="14%" />
    310   <col width="39%" />
    311   </colgroup><tbody><tr>
    312    <th>CVE</th>
    313    <th></th>
    314    <th></th>
    315    <th></th>
    316    <th> AOSP </th>
    317   </tr>
    318   <tr>
    319    <td>CVE-2017-0638</td>
    320    <td><a href="https://android.googlesource.com/platform/external/libgdx/+/a98943dd4aece3024f023f00256607d50dcbcd1e">A-36368305</a></td>
    321    <td>RCE</td>
    322    <td></td>
    323    <td>7.1.1, 7.1.2</td>
    324   </tr>
    325 </tbody></table>
    326 <h2 id="2017-06-05-details">2017-06-05    </h2>
    327 <p>  2017-06-05   
    328        . 
    329       CVE,  ,
    330 <a href="#vulnerability-type"> </a>, <a href="/security/overview/updates-resources.html#severity"></a>, ( ),
    331  AOSP ( ) 
    332   .  
    333 AOSP         ID
    334 .        
    335   ID    .</p>
    336 
    337 <h3 id="kernel-components"> </h3>
    338 <p>        
    339        .</p>
    340 
    341 <table>
    342   <colgroup><col width="17%" />
    343   <col width="19%" />
    344   <col width="9%" />
    345   <col width="14%" />
    346   <col width="39%" />
    347   </colgroup><tbody><tr>
    348    <th>CVE</th>
    349    <th></th>
    350    <th></th>
    351    <th></th>
    352    <th></th>
    353   </tr>
    354   <tr>
    355    <td>CVE-2017-0648</td>
    356    <td>A-36101220<a href="#asterisk">*</a></td>
    357    <td>EoP</td>
    358    <td></td>
    359    <td>FIQ </td>
    360   </tr>
    361   <tr>
    362    <td>CVE-2017-0651</td>
    363    <td>A-35644815<a href="#asterisk">*</a></td>
    364    <td>ID</td>
    365    <td></td>
    366    <td>ION  </td>
    367   </tr>
    368 </tbody></table>
    369 <h3 id="libraries-05"></h3>
    370 <p>         
    371       .</p>
    372 
    373 <table>
    374   <colgroup><col width="17%" />
    375   <col width="19%" />
    376   <col width="9%" />
    377   <col width="14%" />
    378   <col width="39%" />
    379   </colgroup><tbody><tr>
    380    <th>CVE</th>
    381    <th></th>
    382    <th></th>
    383    <th></th>
    384    <th> AOSP </th>
    385   </tr>
    386   <tr>
    387    <td>CVE-2015-7995</td>
    388    <td>A-36810065<a href="#asterisk">*</a></td>
    389    <td>ID</td>
    390    <td></td>
    391    <td>4.4.4</td>
    392   </tr>
    393 </tbody></table>
    394 <h3 id="mediatek-components">MediaTek </h3>
    395 <p>        
    396        .</p>
    397 
    398 <table>
    399   <colgroup><col width="17%" />
    400   <col width="19%" />
    401   <col width="9%" />
    402   <col width="14%" />
    403   <col width="39%" />
    404   </colgroup><tbody><tr>
    405    <th>CVE</th>
    406    <th></th>
    407    <th></th>
    408    <th></th>
    409    <th></th>
    410   </tr>
    411   <tr>
    412    <td>CVE-2017-0636</td>
    413    <td>A-35310230<a href="#asterisk">*</a><br />
    414        M-ALPS03162263</td>
    415    <td>EoP</td>
    416    <td></td>
    417    <td>  </td>
    418   </tr>
    419   <tr>
    420    <td>CVE-2017-0649</td>
    421    <td>A-34468195<a href="#asterisk">*</a><br />
    422        M-ALPS03162283</td>
    423    <td>EoP</td>
    424    <td></td>
    425    <td> </td>
    426   </tr>
    427 </tbody></table>
    428 <h3 id="nvidia-components">NVIDIA </h3>
    429 <p>        
    430        .</p>
    431 
    432 <table>
    433   <colgroup><col width="17%" />
    434   <col width="19%" />
    435   <col width="9%" />
    436   <col width="14%" />
    437   <col width="39%" />
    438   </colgroup><tbody><tr>
    439    <th>CVE</th>
    440    <th></th>
    441    <th></th>
    442    <th></th>
    443    <th></th>
    444   </tr>
    445   <tr>
    446    <td>CVE-2017-6247</td>
    447    <td>A-34386301<a href="#asterisk">*</a><br />
    448        N-CVE-2017-6247</td>
    449    <td>EoP</td>
    450    <td></td>
    451    <td> </td>
    452   </tr>
    453   <tr>
    454    <td>CVE-2017-6248</td>
    455    <td>A-34372667<a href="#asterisk">*</a><br />
    456        N-CVE-2017-6248</td>
    457    <td>EoP</td>
    458    <td></td>
    459    <td> </td>
    460   </tr>
    461 </tbody></table>
    462 <h3 id="qualcomm-components">Qualcomm </h3>
    463 <p>          
    464     .</p>
    465 
    466 <table>
    467   <colgroup><col width="17%" />
    468   <col width="19%" />
    469   <col width="9%" />
    470   <col width="14%" />
    471   <col width="39%" />
    472   </colgroup><tbody><tr>
    473    <th>CVE</th>
    474    <th></th>
    475    <th></th>
    476    <th></th>
    477    <th></th>
    478   </tr>
    479   <tr>
    480    <td>CVE-2017-7371</td>
    481    <td>A-36250786<br />
    482    <a href="https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?id=e02e63b8014f7a0a5ea17a5196fb4ef1283fd1fd">QC-CR#1101054</a></td>
    483    <td>RCE</td>
    484    <td></td>
    485    <td> </td>
    486   </tr>
    487   <tr>
    488    <td>CVE-2017-7365</td>
    489    <td>A-32449913<br />
    490    <a href="https://source.codeaurora.org/quic/la//kernel/lk/commit/?id=da49bf21d1c19a6293d33c985066dc0273c476db">QC-CR#1017009</a></td>
    491    <td>EoP</td>
    492    <td></td>
    493    <td></td>
    494   </tr>
    495   <tr>
    496    <td>CVE-2017-7366</td>
    497    <td>A-36252171<br />
    498    <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=f4c9ffd6cd7960265f38e285ac43cbecf2459e45">QC-CR#1036161</a>
    499 [<a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=7c4d5736d32f91f0cafe6cd86d00e26389970b00">2</a>]</td>
    500    <td>EoP</td>
    501    <td></td>
    502    <td>GPU </td>
    503   </tr>
    504   <tr>
    505    <td>CVE-2017-7367</td>
    506    <td>A-34514708<br />
    507    <a href="https://source.codeaurora.org/quic/la//kernel/lk/commit/?id=07174af1af48c60a41c7136f0c80ffdf4ccc0b57">QC-CR#1008421</a></td>
    508    <td>DoS</td>
    509    <td></td>
    510    <td></td>
    511   </tr>
    512   <tr>
    513    <td>CVE-2016-5861</td>
    514    <td>A-36251375<br />
    515    <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=cf3c97b8b6165f13810e530068fbf94b07f1f77d">QC-CR#1103510</a></td>
    516    <td>EoP</td>
    517    <td></td>
    518    <td> </td>
    519   </tr>
    520   <tr>
    521    <td>CVE-2016-5864</td>
    522    <td>A-36251231<br />
    523    <a href="https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?id=cbc21ceb69cb7bca0643423a7ca982abce3ce50a">QC-CR#1105441</a></td>
    524    <td>EoP</td>
    525    <td></td>
    526    <td> </td>
    527   </tr>
    528   <tr>
    529    <td>CVE-2017-6421</td>
    530    <td>A-36251986<br />
    531    <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=be42c7ff1f0396484882451fd18f47144c8f1b6b">QC-CR#1110563</a></td>
    532    <td>EoP</td>
    533    <td></td>
    534    <td>MStar  </td>
    535   </tr>
    536   <tr>
    537    <td>CVE-2017-7364</td>
    538    <td>A-36252179<br />
    539    <a href="https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?id=3ce6c47d2142fcd2c4c1181afe08630aaae5a267">QC-CR#1113926</a></td>
    540    <td>EoP</td>
    541    <td></td>
    542    <td> </td>
    543   </tr>
    544   <tr>
    545    <td>CVE-2017-7368</td>
    546    <td>A-33452365<br />
    547    <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=143ef972be1621458930ea3fc1def5ebce7b0c5d">QC-CR#1103085</a></td>
    548    <td>EoP</td>
    549    <td></td>
    550    <td> </td>
    551   </tr>
    552   <tr>
    553    <td>CVE-2017-7369</td>
    554    <td>A-33751424<br />
    555    <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.10/commit/?id=75ed08a822cf378ffed0d2f177d06555bd77a006">QC-CR#2009216</a>
    556 [<a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=ae8f1d5f60644983aba7fbab469d0e542a187c6e">2</a>]</td>
    557    <td>EoP</td>
    558    <td></td>
    559    <td> </td>
    560   </tr>
    561   <tr>
    562    <td>CVE-2017-7370</td>
    563    <td>A-34328139<br />
    564    <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=970edf007fbe64b094437541a42477d653802d85">QC-CR#2006159</a></td>
    565    <td>EoP</td>
    566    <td></td>
    567    <td> </td>
    568   </tr>
    569   <tr>
    570    <td>CVE-2017-7372</td>
    571    <td>A-36251497<br />
    572    <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=1806be003731d6d4be55e5b940d14ab772839e13">QC-CR#1110068</a></td>
    573    <td>EoP</td>
    574    <td></td>
    575    <td> </td>
    576   </tr>
    577   <tr>
    578    <td>CVE-2017-7373</td>
    579    <td>A-36251984<br />
    580    <a href="https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=e5eb0d3aa6fe62ee437a2269a1802b1a72f61b75">QC-CR#1090244</a></td>
    581    <td>EoP</td>
    582    <td></td>
    583    <td> </td>
    584   </tr>
    585   <tr>
    586    <td>CVE-2017-8233</td>
    587    <td>A-34621613<br />
    588    <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=64b7bc25e019dd07e8042e0a6ec6dc6a1dd0c385">QC-CR#2004036</a></td>
    589    <td>EoP</td>
    590    <td></td>
    591    <td> </td>
    592   </tr>
    593   <tr>
    594    <td>CVE-2017-8234</td>
    595    <td>A-36252121<br />
    596    <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=6266f954a52641f550ef71653ea83c80bdd083be">QC-CR#832920</a></td>
    597    <td>EoP</td>
    598    <td></td>
    599    <td> </td>
    600   </tr>
    601   <tr>
    602    <td>CVE-2017-8235</td>
    603    <td>A-36252376<br />
    604    <a href="https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?id=7e4424a1b5f6a6536066cca7aac2c3a23fd39f6f">QC-CR#1083323</a></td>
    605    <td>EoP</td>
    606    <td></td>
    607    <td> </td>
    608   </tr>
    609   <tr>
    610    <td>CVE-2017-8236</td>
    611    <td>A-35047217<br />
    612    <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=cf0d31bc3b04cf2db7737d36b11a5bf50af0c1db">QC-CR#2009606</a></td>
    613    <td>EoP</td>
    614    <td></td>
    615    <td>IPA </td>
    616   </tr>
    617   <tr>
    618    <td>CVE-2017-8237</td>
    619    <td>A-36252377<br />
    620    <a href="https://source.codeaurora.org/quic/la//kernel/msm-3.18/commit/?id=342d16ac6fb01e304ec75344c693257e00628ecf">QC-CR#1110522</a></td>
    621    <td>EoP</td>
    622    <td></td>
    623    <td> </td>
    624   </tr>
    625   <tr>
    626    <td>CVE-2017-8242</td>
    627    <td>A-34327981<br />
    628    <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=6a3b8afdf97e77c0b64005b23fa6d32025d922e5">QC-CR#2009231</a></td>
    629    <td>EoP</td>
    630    <td></td>
    631    <td>Secure Execution Environment Communication </td>
    632   </tr>
    633   <tr>
    634    <td>CVE-2017-8239</td>
    635    <td>A-36251230<br />
    636    <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=01db0e012f86b8ba6974e5cb9905261a552a0610">QC-CR#1091603</a></td>
    637    <td>ID</td>
    638    <td></td>
    639    <td> </td>
    640   </tr>
    641   <tr>
    642    <td>CVE-2017-8240</td>
    643    <td>A-36251985<br />
    644    <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=22b8b6608174c1308208d5bc6c143f4998744547">QC-CR#856379</a></td>
    645    <td>ID</td>
    646    <td></td>
    647    <td>  </td>
    648   </tr>
    649   <tr>
    650    <td>CVE-2017-8241</td>
    651    <td>A-34203184<br />
    652    <a href="https://source.codeaurora.org/quic/la//platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=90213394b7efb28fa511b2eaebc1343ae3b54724">QC-CR#1069175</a></td>
    653    <td>ID</td>
    654    <td></td>
    655    <td>Wi-Fi </td>
    656   </tr>
    657 </tbody></table>
    658 <h3 id="synaptics-components">Synaptics </h3>
    659 <p>        
    660       .</p>
    661 
    662 <table>
    663   <colgroup><col width="17%" />
    664   <col width="19%" />
    665   <col width="9%" />
    666   <col width="14%" />
    667   <col width="39%" />
    668   </colgroup><tbody><tr>
    669    <th>CVE</th>
    670    <th></th>
    671    <th></th>
    672    <th></th>
    673    <th></th>
    674   </tr>
    675   <tr>
    676    <td>CVE-2017-0650</td>
    677    <td>A-35472278<a href="#asterisk">*</a></td>
    678    <td>EoP</td>
    679    <td></td>
    680    <td> </td>
    681   </tr>
    682 </tbody></table>
    683 <h3 id="qualcomm-closed-source-components">Qualcomm  
    684 </h3>
    685 <p>  Qualcomm    Qualcomm AMSS
    686 2014~2016     .  
    687    Android      Android 
    688  .    Qualcomm    .</p>
    689 
    690 <table>
    691   <colgroup><col width="17%" />
    692   <col width="19%" />
    693   <col width="9%" />
    694   <col width="14%" />
    695   <col width="39%" />
    696   </colgroup><tbody><tr>
    697    <th>CVE</th>
    698    <th></th>
    699    <th></th>
    700    <th></th>
    701    <th></th>
    702   </tr>
    703   <tr>
    704    <td>CVE-2014-9960</td>
    705    <td>A-37280308<a href="#asterisk">*</a><br />
    706        QC-CR#381837</td>
    707    <td> </td>
    708    <td></td>
    709    <td>  </td>
    710   </tr>
    711   <tr>
    712    <td>CVE-2014-9961</td>
    713    <td>A-37279724<a href="#asterisk">*</a><br />
    714        QC-CR#581093</td>
    715    <td> </td>
    716    <td></td>
    717    <td>  </td>
    718   </tr>
    719   <tr>
    720    <td>CVE-2014-9953</td>
    721    <td>A-36714770<a href="#asterisk">*</a><br />
    722        QC-CR#642173</td>
    723    <td> </td>
    724    <td></td>
    725    <td>  </td>
    726   </tr>
    727   <tr>
    728    <td>CVE-2014-9967</td>
    729    <td>A-37281466<a href="#asterisk">*</a><br />
    730        QC-CR#739110</td>
    731    <td> </td>
    732    <td></td>
    733    <td>  </td>
    734   </tr>
    735   <tr>
    736    <td>CVE-2015-9026</td>
    737    <td>A-37277231<a href="#asterisk">*</a><br />
    738        QC-CR#748397</td>
    739    <td> </td>
    740    <td></td>
    741    <td>  </td>
    742   </tr>
    743   <tr>
    744    <td>CVE-2015-9027</td>
    745    <td>A-37279124<a href="#asterisk">*</a><br />
    746        QC-CR#748407</td>
    747    <td> </td>
    748    <td></td>
    749    <td>  </td>
    750   </tr>
    751   <tr>
    752    <td>CVE-2015-9008</td>
    753    <td>A-36384689<a href="#asterisk">*</a><br />
    754        QC-CR#762111</td>
    755    <td> </td>
    756    <td></td>
    757    <td>  </td>
    758   </tr>
    759   <tr>
    760    <td>CVE-2015-9009</td>
    761    <td>A-36393600<a href="#asterisk">*</a><br />
    762        QC-CR#762182</td>
    763    <td> </td>
    764    <td></td>
    765    <td>  </td>
    766   </tr>
    767   <tr>
    768    <td>CVE-2015-9010</td>
    769    <td>A-36393101<a href="#asterisk">*</a><br />
    770        QC-CR#758752</td>
    771    <td> </td>
    772    <td></td>
    773    <td>  </td>
    774   </tr>
    775   <tr>
    776    <td>CVE-2015-9011</td>
    777    <td>A-36714882<a href="#asterisk">*</a><br />
    778        QC-CR#762167</td>
    779    <td> </td>
    780    <td></td>
    781    <td>  </td>
    782   </tr>
    783   <tr>
    784    <td>CVE-2015-9024</td>
    785    <td>A-37265657<a href="#asterisk">*</a><br />
    786        QC-CR#740680</td>
    787    <td> </td>
    788    <td></td>
    789    <td>  </td>
    790   </tr>
    791   <tr>
    792    <td>CVE-2015-9012</td>
    793    <td>A-36384691<a href="#asterisk">*</a><br />
    794        QC-CR#746617</td>
    795    <td> </td>
    796    <td></td>
    797    <td>  </td>
    798   </tr>
    799   <tr>
    800    <td>CVE-2015-9013</td>
    801    <td>A-36393251<a href="#asterisk">*</a><br />
    802        QC-CR#814373</td>
    803    <td> </td>
    804    <td></td>
    805    <td>  </td>
    806   </tr>
    807   <tr>
    808    <td>CVE-2015-9014</td>
    809    <td>A-36393750<a href="#asterisk">*</a><br />
    810        QC-CR#855220</td>
    811    <td> </td>
    812    <td></td>
    813    <td>  </td>
    814   </tr>
    815   <tr>
    816    <td>CVE-2015-9015</td>
    817    <td>A-36714120<a href="#asterisk">*</a><br />
    818        QC-CR#701858</td>
    819    <td> </td>
    820    <td></td>
    821    <td>  </td>
    822   </tr>
    823   <tr>
    824    <td>CVE-2015-9029</td>
    825    <td>A-37276981<a href="#asterisk">*</a><br />
    826        QC-CR#827837</td>
    827    <td> </td>
    828    <td></td>
    829    <td>  </td>
    830   </tr>
    831   <tr>
    832    <td>CVE-2016-10338</td>
    833    <td>A-37277738<a href="#asterisk">*</a><br />
    834        QC-CR#987699</td>
    835    <td> </td>
    836    <td></td>
    837    <td>  </td>
    838   </tr>
    839   <tr>
    840    <td>CVE-2016-10336</td>
    841    <td>A-37278436<a href="#asterisk">*</a><br />
    842        QC-CR#973605</td>
    843    <td> </td>
    844    <td></td>
    845    <td>  </td>
    846   </tr>
    847   <tr>
    848    <td>CVE-2016-10333</td>
    849    <td>A-37280574<a href="#asterisk">*</a><br />
    850        QC-CR#947438</td>
    851    <td> </td>
    852    <td></td>
    853    <td>  </td>
    854   </tr>
    855   <tr>
    856    <td>CVE-2016-10341</td>
    857    <td>A-37281667<a href="#asterisk">*</a><br />
    858        QC-CR#991476</td>
    859    <td> </td>
    860    <td></td>
    861    <td>  </td>
    862   </tr>
    863   <tr>
    864    <td>CVE-2016-10335</td>
    865    <td>A-37282802<a href="#asterisk">*</a><br />
    866        QC-CR#961142</td>
    867    <td> </td>
    868    <td></td>
    869    <td>  </td>
    870   </tr>
    871   <tr>
    872    <td>CVE-2016-10340</td>
    873    <td>A-37280614<a href="#asterisk">*</a><br />
    874        QC-CR#989028</td>
    875    <td> </td>
    876    <td></td>
    877    <td>  </td>
    878   </tr>
    879   <tr>
    880    <td>CVE-2016-10334</td>
    881    <td>A-37280664<a href="#asterisk">*</a><br />
    882        QC-CR#949933</td>
    883    <td> </td>
    884    <td></td>
    885    <td>  </td>
    886   </tr>
    887   <tr>
    888    <td>CVE-2016-10339</td>
    889    <td>A-37280575<a href="#asterisk">*</a><br />
    890        QC-CR#988502</td>
    891    <td> </td>
    892    <td></td>
    893    <td>  </td>
    894   </tr>
    895   <tr>
    896    <td>CVE-2016-10298</td>
    897    <td>A-36393252<a href="#asterisk">*</a><br />
    898        QC-CR#1020465</td>
    899    <td> </td>
    900    <td></td>
    901    <td>  </td>
    902   </tr>
    903   <tr>
    904    <td>CVE-2016-10299</td>
    905    <td>A-32577244<a href="#asterisk">*</a><br />
    906        QC-CR#1058511</td>
    907    <td> </td>
    908    <td></td>
    909    <td>  </td>
    910   </tr>
    911   <tr>
    912    <td>CVE-2014-9954</td>
    913    <td>A-36388559<a href="#asterisk">*</a><br />
    914        QC-CR#552880</td>
    915    <td> </td>
    916    <td></td>
    917    <td>  </td>
    918   </tr>
    919   <tr>
    920    <td>CVE-2014-9955</td>
    921    <td>A-36384686<a href="#asterisk">*</a><br />
    922        QC-CR#622701</td>
    923    <td> </td>
    924    <td></td>
    925    <td>  </td>
    926   </tr>
    927   <tr>
    928    <td>CVE-2014-9956</td>
    929    <td>A-36389611<a href="#asterisk">*</a><br />
    930        QC-CR#638127</td>
    931    <td> </td>
    932    <td></td>
    933    <td>  </td>
    934   </tr>
    935   <tr>
    936    <td>CVE-2014-9957</td>
    937    <td>A-36387564<a href="#asterisk">*</a><br />
    938        QC-CR#638984</td>
    939    <td> </td>
    940    <td></td>
    941    <td>  </td>
    942   </tr>
    943   <tr>
    944    <td>CVE-2014-9958</td>
    945    <td>A-36384774<a href="#asterisk">*</a><br />
    946        QC-CR#638135</td>
    947    <td> </td>
    948    <td></td>
    949    <td>  </td>
    950   </tr>
    951   <tr>
    952    <td>CVE-2014-9962</td>
    953    <td>A-37275888<a href="#asterisk">*</a><br />
    954        QC-CR#656267</td>
    955    <td> </td>
    956    <td></td>
    957    <td>  </td>
    958   </tr>
    959   <tr>
    960    <td>CVE-2014-9963</td>
    961    <td>A-37276741<a href="#asterisk">*</a><br />
    962        QC-CR#657771</td>
    963    <td> </td>
    964    <td></td>
    965    <td>  </td>
    966   </tr>
    967   <tr>
    968    <td>CVE-2014-9959</td>
    969    <td>A-36383694<a href="#asterisk">*</a><br />
    970        QC-CR#651900</td>
    971    <td> </td>
    972    <td></td>
    973    <td>  </td>
    974   </tr>
    975   <tr>
    976    <td>CVE-2014-9964</td>
    977    <td>A-37280321<a href="#asterisk">*</a><br />
    978        QC-CR#680778</td>
    979    <td> </td>
    980    <td></td>
    981    <td>  </td>
    982   </tr>
    983   <tr>
    984    <td>CVE-2014-9965</td>
    985    <td>A-37278233<a href="#asterisk">*</a><br />
    986        QC-CR#711585</td>
    987    <td> </td>
    988    <td></td>
    989    <td>  </td>
    990   </tr>
    991   <tr>
    992    <td>CVE-2014-9966</td>
    993    <td>A-37282854<a href="#asterisk">*</a><br />
    994        QC-CR#727398</td>
    995    <td> </td>
    996    <td></td>
    997    <td>  </td>
    998   </tr>
    999   <tr>
   1000    <td>CVE-2015-9023</td>
   1001    <td>A-37276138<a href="#asterisk">*</a><br />
   1002        QC-CR#739802</td>
   1003    <td> </td>
   1004    <td></td>
   1005    <td>  </td>
   1006   </tr>
   1007   <tr>
   1008    <td>CVE-2015-9020</td>
   1009    <td>A-37276742<a href="#asterisk">*</a><br />
   1010        QC-CR#733455</td>
   1011    <td> </td>
   1012    <td></td>
   1013    <td>  </td>
   1014   </tr>
   1015   <tr>
   1016    <td>CVE-2015-9021</td>
   1017    <td>A-37276743<a href="#asterisk">*</a><br />
   1018        QC-CR#735148</td>
   1019    <td> </td>
   1020    <td></td>
   1021    <td>  </td>
   1022   </tr>
   1023   <tr>
   1024    <td>CVE-2015-9025</td>
   1025    <td>A-37276744<a href="#asterisk">*</a><br />
   1026        QC-CR#743985</td>
   1027    <td> </td>
   1028    <td></td>
   1029    <td>  </td>
   1030   </tr>
   1031   <tr>
   1032    <td>CVE-2015-9022</td>
   1033    <td>A-37280226<a href="#asterisk">*</a><br />
   1034        QC-CR#736146</td>
   1035    <td> </td>
   1036    <td></td>
   1037    <td>  </td>
   1038   </tr>
   1039   <tr>
   1040    <td>CVE-2015-9028</td>
   1041    <td>A-37277982<a href="#asterisk">*</a><br />
   1042        QC-CR#762764</td>
   1043    <td> </td>
   1044    <td></td>
   1045    <td>  </td>
   1046   </tr>
   1047   <tr>
   1048    <td>CVE-2015-9031</td>
   1049    <td>A-37275889<a href="#asterisk">*</a><br />
   1050        QC-CR#866015</td>
   1051    <td> </td>
   1052    <td></td>
   1053    <td>  </td>
   1054   </tr>
   1055   <tr>
   1056    <td>CVE-2015-9032</td>
   1057    <td>A-37279125<a href="#asterisk">*</a><br />
   1058        QC-CR#873202</td>
   1059    <td> </td>
   1060    <td></td>
   1061    <td>  </td>
   1062   </tr>
   1063   <tr>
   1064    <td>CVE-2015-9033</td>
   1065    <td>A-37276139<a href="#asterisk">*</a><br />
   1066        QC-CR#892541</td>
   1067    <td> </td>
   1068    <td></td>
   1069    <td>  </td>
   1070   </tr>
   1071   <tr>
   1072    <td>CVE-2015-9030</td>
   1073    <td>A-37282907<a href="#asterisk">*</a><br />
   1074        QC-CR#854667</td>
   1075    <td> </td>
   1076    <td></td>
   1077    <td>  </td>
   1078   </tr>
   1079   <tr>
   1080    <td>CVE-2016-10332</td>
   1081    <td>A-37282801<a href="#asterisk">*</a><br />
   1082        QC-CR#906713<br />
   1083        QC-CR#917701<br />
   1084        QC-CR#917702</td>
   1085    <td> </td>
   1086    <td></td>
   1087    <td>  </td>
   1088   </tr>
   1089   <tr>
   1090    <td>CVE-2016-10337</td>
   1091    <td>A-37280665<a href="#asterisk">*</a><br />
   1092        QC-CR#977632</td>
   1093    <td> </td>
   1094    <td></td>
   1095    <td>  </td>
   1096   </tr>
   1097   <tr>
   1098    <td>CVE-2016-10342</td>
   1099    <td>A-37281763<a href="#asterisk">*</a><br />
   1100        QC-CR#988941</td>
   1101    <td> </td>
   1102    <td></td>
   1103    <td>  </td>
   1104   </tr>
   1105 </tbody></table>
   1106 <h2 id="google-device-updates">Google  </h2>
   1107 <p>    (OTA)     Google 
   1108    . The Google   
   1109 <a href="https://developers.google.com/android/nexus/images">Google  </a>  
   1110 .</p>
   1111 
   1112 <table>
   1113   <colgroup><col width="25%" />
   1114   <col width="75%" />
   1115   </colgroup><tbody><tr>
   1116    <th>Google </th>
   1117    <th>  </th>
   1118   </tr>
   1119   <tr>
   1120    <td>Pixel/Pixel XL</td>
   1121    <td>2017 6 5</td>
   1122   </tr>
   1123   <tr>
   1124    <td>Nexus 5X</td>
   1125    <td>2017 6 5</td>
   1126   </tr>
   1127   <tr>
   1128    <td>Nexus 6</td>
   1129    <td>2017 6 5</td>
   1130   </tr>
   1131   <tr>
   1132    <td>Nexus 6P</td>
   1133    <td>2017 6 5</td>
   1134   </tr>
   1135   <tr>
   1136    <td>Nexus 9</td>
   1137    <td>2017 6 5</td>
   1138   </tr>
   1139   <tr>
   1140    <td>Nexus Player</td>
   1141    <td>2017 6 5</td>
   1142   </tr>
   1143   <tr>
   1144    <td>Pixel C</td>
   1145    <td>2017 6 5</td>
   1146   </tr>
   1147 </tbody></table>
   1148 <h2 id="acknowledgements"> </h2>
   1149 <p>    .</p>
   1150 
   1151 <table>
   1152   <colgroup><col width="17%" />
   1153   <col width="83%" />
   1154   </colgroup><tbody><tr>
   1155    <th>CVE</th>
   1156    <th></th>
   1157   </tr>
   1158   <tr>
   1159    <td>CVE-2017-0643, CVE-2017-0641</td>
   1160    <td>Trend Micro Ecular Xu()</td>
   1161   </tr>
   1162   <tr>
   1163    <td>CVE-2017-0645, CVE-2017-0639</td>
   1164    <td><a href="http://www.ms509.com">MS509Team</a> En He(<a href="https://twitter.com/heeeeen4x">@heeeeen4x</a>),
   1165 Bo Liu</td>
   1166   </tr>
   1167   <tr>
   1168    <td>CVE-2017-0649</td>
   1169    <td>Qihoo 360 Technology Co. Ltd. IceSword Lab
   1170 Gengjia Chen(<a href="https://twitter.com/chengjia4574">@chengjia4574</a>), <a href="http://weibo.com/jfpan">pjf</a></td>
   1171   </tr>
   1172   <tr>
   1173    <td>CVE-2017-0646</td>
   1174    <td>Tencent PC Manager Godzheng( -<a href="https://twitter.com/VirtualSeekers">@VirtualSeekers</a>)</td>
   1175   </tr>
   1176   <tr>
   1177    <td>CVE-2017-0636</td>
   1178    <td>Shellphish Grill Team Jake Corina, Nick Stephens</td>
   1179   </tr>
   1180   <tr>
   1181    <td>CVE-2017-8233</td>
   1182    <td>Qihoo 360 IceSword Lab Jianqiang Zhao(<a href="https://twitter.com/jianqiangzhao">@jianqiangzhao</a>), <a href="http://weibo.com/jfpan">pjf </a></td>
   1183   </tr>
   1184   <tr>
   1185    <td>CVE-2017-7368</td>
   1186    <td><a href="http://c0reteam.org">C0RE Team</a> Lubo Zhang(<a href="mailto:zlbzlb815 (a] 163.com">zlbzlb815 (a] 163.com</a>), Yuan-Tsung Lo(<a href="mailto:computernik (a] gmail.com">computernik (a] gmail.com</a>),
   1187 Xuxian Jiang</td>
   1188   </tr>
   1189   <tr>
   1190    <td>CVE-2017-8242</td>
   1191    <td>Tesla's Product Security Team
   1192 Nathan Crandall(<a href="https://twitter.com/natecray">@natecray</a>)</td>
   1193   </tr>
   1194   <tr>
   1195    <td>CVE-2017-0650</td>
   1196    <td>Ben Gurion University Cyber Lab Omer Shwartz, Amir Cohen,
   1197 Dr. Asaf Shabtai, Dr. Yossi Oren</td>
   1198   </tr>
   1199   <tr>
   1200    <td>CVE-2017-0648</td>
   1201    <td>HCL Technologies <a href="https://alephsecurity.com/">Aleph Research</a> Roee Hay(<a href="https://twitter.com/roeehay">@roeehay</a>)</td>
   1202   </tr>
   1203   <tr>
   1204    <td>CVE-2017-7369, CVE-2017-6249, CVE-2017-6247, CVE-2017-6248</td>
   1205    <td>TrendMicro sevenshen(<a href="https://twitter.com/lingtongshen">@lingtongshen</a>)</td>
   1206   </tr>
   1207   <tr>
   1208    <td>CVE-2017-0642, CVE-2017-0637, CVE-2017-0638</td>
   1209    <td>Vasily Vasiliev</td>
   1210   </tr>
   1211   <tr>
   1212    <td>CVE-2017-0640</td>
   1213    <td><a href="http://www.trendmicro.com">Trend Micro</a> <a href="http://blog.trendmicro.com/trendlabs-security-intelligence/category/mobile/">Mobile
   1214 Threat Response Team</a> V.E.O(<a href="https://twitter.com/vysea">@VYSEa</a>)</td>
   1215   </tr>
   1216   <tr>
   1217    <td>CVE-2017-8236</td>
   1218    <td>Tencent Security Platform Department Xiling Gong</td>
   1219   </tr>
   1220   <tr>
   1221    <td>CVE-2017-0647</td>
   1222    <td>Qihoo 360 Qex Team
   1223 Yangkang(<a href="https://twitter.com/dnpushme">@dnpushme</a>), Liyadong</td>
   1224   </tr>
   1225   <tr>
   1226    <td>CVE-2017-7370</td>
   1227    <td>Qihoo 360 Technology Co. Ltd. IceSword Lab
   1228 Yonggang Guo(<a href="https://twitter.com/guoygang">@guoygang</a>)</td>
   1229   </tr>
   1230   <tr>
   1231    <td>CVE-2017-0651</td>
   1232    <td><a href="http://c0reteam.org">C0RE Team</a> Yuan-Tsung Lo(<a href="mailto:computernik (a] gmail.com">computernik (a] gmail.com</a>),
   1233 Xuxian Jiang</td>
   1234   </tr>
   1235   <tr>
   1236    <td>CVE-2017-8241</td>
   1237    <td>Google Zubin Mithra</td>
   1238   </tr>
   1239 </tbody></table>
   1240 <h2 id="common-questions-and-answers">   </h2>
   1241 <p>            .</p>
   1242 
   1243 <p><strong>1.          ?
   1244 </strong></p>
   1245 
   1246 <p>      
   1247 <a href="https://support.google.com/pixelphone/answer/4457705#pixel_phones&nexus_devices">Pixel  Nexus  </a>
   1248   .</p>
   1249 <ul>
   1250 <li>2017-06-01       2017-06-01
   1251     .</li>
   1252 <li>2017-06-05          
   1253   2017-06-05     .</li></ul>
   1254 <p>       
   1255    .</p>
   1256 <ul>
   1257 <li>[ro.build.version.security_patch]:[2017-06-01]</li>
   1258 <li>[ro.build.version.security_patch]:[2017-06-05]</li></ul>
   1259 <p><strong>2.          ?</strong></p>
   1260 
   1261 <p>  Android   Android   
   1262                . Android       
   1263       .</p>
   1264 <ul>
   1265 <li>2017 6 1         
   1266          
   1267  .</li>
   1268 <li>2017 6 5         
   1269         .</li></ul>
   1270 <p>           
   1271 .</p>
   1272 
   1273 <p id="vulnerability-type"><strong>3. <em></em>    ?</strong></p>
   1274 
   1275 <p>   <em></em>   
   1276    .</p>
   1277 
   1278 <table>
   1279   <colgroup><col width="25%" />
   1280   <col width="75%" />
   1281   </colgroup><tbody><tr>
   1282    <th></th>
   1283    <th></th>
   1284   </tr>
   1285   <tr>
   1286    <td>RCE</td>
   1287    <td>  </td>
   1288   </tr>
   1289   <tr>
   1290    <td>EoP</td>
   1291    <td> </td>
   1292   </tr>
   1293   <tr>
   1294    <td>ID</td>
   1295    <td> </td>
   1296   </tr>
   1297   <tr>
   1298    <td>DoS</td>
   1299    <td> </td>
   1300   </tr>
   1301   <tr>
   1302    <td> </td>
   1303    <td> </td>
   1304   </tr>
   1305 </tbody></table>
   1306 <p><strong>4. <em></em>    ?</strong></p>
   1307 
   1308 <p>   <em></em>      
   1309      .</p>
   1310 
   1311 <table>
   1312   <colgroup><col width="25%" />
   1313   <col width="75%" />
   1314   </colgroup><tbody><tr>
   1315    <th></th>
   1316    <th></th>
   1317   </tr>
   1318   <tr>
   1319    <td>A-</td>
   1320    <td>Android  ID</td>
   1321   </tr>
   1322   <tr>
   1323    <td>QC-</td>
   1324    <td>Qualcomm  </td>
   1325   </tr>
   1326   <tr>
   1327    <td>M-</td>
   1328    <td>MediaTek  </td>
   1329   </tr>
   1330   <tr>
   1331    <td>N-</td>
   1332    <td>NVIDIA  </td>
   1333   </tr>
   1334   <tr>
   1335    <td>B-</td>
   1336    <td>Broadcom  </td>
   1337   </tr>
   1338 </tbody></table>
   1339 <p id="asterisk"><strong>5. <em></em>  Android  ID   <a href="#asterisk">*</a> 
   1340  ?</strong></p>
   1341 
   1342 <p>   <em></em>  Android  ID  <a href="#asterisk">*</a>  .     <a href="https://developers.google.com/android/nexus/drivers">Google  </a>
   1343  Nexus      .</p>
   1344 
   1345 <h2 id="versions"></h2>
   1346 <table>
   1347   <colgroup><col width="25%" />
   1348   <col width="25%" />
   1349   <col width="50%" />
   1350   </colgroup><tbody><tr>
   1351    <th></th>
   1352    <th></th>
   1353    <th></th>
   1354   </tr>
   1355   <tr>
   1356    <td>1.0/</td>
   1357    <td>2017 6 5</td>
   1358    <td> </td>
   1359   </tr>
   1360   <tr>
   1361     <td>1.1</td>
   1362     <td>2017 6 7</td>
   1363     <td>  AOSP  </td>
   1364   </tr>
   1365 </tbody></table>
   1366 
   1367 </body></html>