In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.
No PoCs from references.
- https://github.com/jiayy/android_vuln_poc-exp