In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in an IOCTL handler potentially leading to an integer overflow and then an out-of-bounds write.
No PoCs from references.
- https://github.com/guoygang/vul-guoygang