Insufficient Minimum Calculation in Qualcomm EHCI-MSM2 USB Driver

Insufficient Minimum Calculation in Qualcomm EHCI-MSM2 USB Driver

CVE-2014-9899 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:N/A:N

drivers/usb/host/ehci-msm2.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices omits certain minimum calculations before copying data, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 28803909 and Qualcomm internal bug CR547910.

Learn more about our Cis Benchmark Audit For Google Android.