CVE-2017-11076

CRITICAL
Published Nov 26, 2024 Modified Jan 9, 2025 CWE-823 CWE-119

Description

On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.

CVSS v3.1 Score

9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-823 CWE-823
CWE-119 Buffer Overflow

Affected Products

Vendor Product
qualcomm msm8909w_firmware
qualcomm msm8909w
qualcomm msm8996au_firmware
qualcomm msm8996au
qualcomm sd_210_firmware
qualcomm sd_210
qualcomm sd_212_firmware
qualcomm sd_212
qualcomm sd_205_firmware
qualcomm sd_205
qualcomm sd_425_firmware
qualcomm sd_425
qualcomm sd_427_firmware
qualcomm sd_427
qualcomm sd_430_firmware
qualcomm sd_430
qualcomm sd_435_firmware
qualcomm sd_435
qualcomm sd_450_firmware
qualcomm sd_450
qualcomm sd_615_firmware
qualcomm sd_615
qualcomm sd_616_firmware
qualcomm sd_616
qualcomm sd_415_firmware
qualcomm sd_415
qualcomm sd_625_firmware
qualcomm sd_625
qualcomm sd_810_firmware
qualcomm sd_810
qualcomm sd_820_firmware
qualcomm sd_820
qualcomm sd_820a_firmware
qualcomm sd_820a
qualcomm sd_835_firmware
qualcomm sd_835
qualcomm sd_845_firmware
qualcomm sd_845
qualcomm sdm429_firmware
qualcomm sdm429
qualcomm sdm439_firmware
qualcomm sdm439
qualcomm sdm630_firmware
qualcomm sdm630
qualcomm sdm632_firmware
qualcomm sdm632
qualcomm sdm636_firmware
qualcomm sdm636
qualcomm sdm660_firmware
qualcomm sdm660
qualcomm sdm710_firmware
qualcomm sdm710
qualcomm snapdragon_high_med_2016_firmware
qualcomm snapdragon_high_med_2016

References

Frequently Asked Questions

What is CVE-2017-11076? +
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. It has a CVSS v3.1 base score of 9.8 (CRITICAL).
How severe is CVE-2017-11076? +
CVE-2017-11076 has a CVSS v3.1 score of 9.8 out of 10, rated CRITICAL. This is a critical vulnerability that should be patched immediately.
What products are affected by CVE-2017-11076? +
CVE-2017-11076 affects products from qualcomm, specifically: msm8909w, msm8909w_firmware, msm8996au, msm8996au_firmware, sd_205, sd_205_firmware, sd_210, sd_210_firmware, sd_212, sd_212_firmware, sd_415, sd_415_firmware, sd_425, sd_425_firmware, sd_427, sd_427_firmware, sd_430, sd_430_firmware, sd_435, sd_435_firmware, sd_450, sd_450_firmware, sd_615, sd_615_firmware, sd_616, sd_616_firmware, sd_625, sd_625_firmware, sd_810, sd_810_firmware, sd_820, sd_820_firmware, sd_820a, sd_820a_firmware, sd_835, sd_835_firmware, sd_845, sd_845_firmware, sdm429, sdm429_firmware, sdm439, sdm439_firmware, sdm630, sdm630_firmware, sdm632, sdm632_firmware, sdm636, sdm636_firmware, sdm660, sdm660_firmware, sdm710, sdm710_firmware, snapdragon_high_med_2016, snapdragon_high_med_2016_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2017-11076? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2017-11076 — free, no signup required.

Start Free Scan