Die Sicherheitspatches für den Monat Mai sind da. Nexus- und Pixel-Nutzer können ihre Geräte bereits auf den neuesten Stand bringen. Besitzer von Geräten anderer Hersteller wie Samsung oder LG müssen sich noch etwas gedulden bis das Sicherheitsupdate auch bei ihnen ankommt.
Der neue Monat ist gerade erst gestartet und schon hat Google frische Sicherheitspatches veröffentlicht. Wie immer gibt es zwei Pakete. Das erste Paket mit der Sicherheitspatch-Ebene 1. Mai 2017 schließt 20 Schwachstellen. Davon besitzen 6 eine kritische und 8 eine hohe Einstufung. Das größere zweite Paket mit der Sicherheitspatch-Ebene 5. Mai 2017 stopft insgesamt 98 Lücken, wovon 23 als kritisch und 59 hoch als eingestuft wurden.
Wer ein Nexus- oder Pixel-Gerät in der Nähe hat, kann bereits das neue Update installieren. Zu den unterstützten Modellen gehören das Nexus 6 (Build N6F27C), Nexus 5X (N2G47O), Nexus 6P (N2G47O), Nexus 9 (N4F27B), Nexus Player (N2G47R), Pixel/Pixel XL (N2G47O, Deutsche Telekom: N2G47T, Verizon: NHG47L) sowie Pixel C (N2G47O). Benötigt jemand die Factory Images für das jeweilige Gerät, der findet die Dateien auf dieser Seite. Die OTA Images gibt es auf dieser Seite.
Android-Sicherheitspatch-Ebene 1. Mai 2017:
| Issue | CVE | Severity |
| Remote code execution vulnerability in Mediaserver | CVE-2017-0587, CVE-2017-0588, CVE-2017-0589, CVE-2017-0590, CVE-2017-0591, CVE-2017-0592 |
Critical |
| Elevation of privilege vulnerability in Framework APIs | CVE-2017-0593 | High |
| Elevation of privilege vulnerability in Mediaserver | CVE-2017-0594, CVE-2017-0595, CVE-2017-0596 |
High |
| Elevation of privilege vulnerability in Audioserver | CVE-2017-0597 | High |
| Information disclosure vulnerability in Framework APIs | CVE-2017-0598 | High |
| Denial of service vulnerability in Mediaserver | CVE-2017-0599, CVE-2017-0600 |
High |
| Elevation of privilege vulnerability in Bluetooth | CVE-2017-0601 | Moderate |
| Information disclosure vulnerability in File-Based Encryption | CVE-2017-0493 | Moderate |
| Information disclosure vulnerability in Bluetooth | CVE-2017-0602 | Moderate |
| Information disclosure vulnerability in OpenSSL & BoringSSL | CVE-2016-7056 | Moderate |
| Denial of service vulnerability in Mediaserver | CVE-2017-0603 | Moderate |
| Denial of service vulnerability in Mediaserver | CVE-2017-0635 | Low |
Android-Sicherheitspatch-Ebene 5. Mai 2017:
| Issue | CVE | Severity |
| Remote code execution vulnerability in GIFLIB | CVE-2015-7555 | Critical |
| Elevation of privilege vulnerability in MediaTek touchscreen driver | CVE-2016-10274 | Critical |
| Elevation of privilege vulnerability in Qualcomm bootloader | CVE-2016-10275, CVE-2016-10276 |
Critical |
| Elevation of privilege vulnerability in kernel sound subsystem | CVE-2016-9794 | Critical |
| Elevation of privilege vulnerability in Motorola bootloader | CVE-2016-10277 | Critical |
| Elevation of privilege vulnerability in NVIDIA video driver | CVE-2017-0331 | Critical |
| Elevation of privilege vulnerability in Qualcomm power driver | CVE-2017-0604 | Critical |
| Elevation of privilege vulnerability in kernel trace subsystem | CVE-2017-0605 | Critical |
| Vulnerabilities in Qualcomm components | CVE-2016-10240 (C), CVE-2016-10241 (C), CVE-2016-10278 (H), CVE-2016-10279 (H) |
Critical (C)/High (H) |
| Remote code execution vulnerability in libxml2 | CVE-2016-5131 | High |
| Elevation of privilege vulnerability in MediaTek thermal driver | CVE-2016-10280, CVE-2016-10281, CVE-2016-10282 |
High |
| Elevation of privilege vulnerability in Qualcomm Wi-Fi driver | CVE-2016-10283 | High |
| Elevation of privilege vulnerability in Qualcomm video driver | CVE-2016-10284, CVE-2016-10285, CVE-2016-10286 |
High |
| Elevation of privilege vulnerability in kernel performance subsystem | CVE-2015-9004 | High |
| Elevation of privilege vulnerability in Qualcomm sound driver | CVE-2016-10287, CVE-2017-0606, CVE-2016-5860, CVE-2016-5867, CVE-2017-0607, CVE-2017-0608, CVE-2017-0609, CVE-2016-5859, CVE-2017-0610, CVE-2017-0611, CVE-2016-5853 |
High |
| Elevation of privilege vulnerability in Qualcomm LED driver | CVE-2016-10288 | High |
| Elevation of privilege vulnerability in Qualcomm crypto driver | CVE-2016-10289 | High |
| Elevation of privilege vulnerability in Qualcomm shared memory driver | CVE-2016-10290 | High |
| Elevation of privilege vulnerability in Qualcomm Slimbus driver | CVE-2016-10291 | High |
| Elevation of privilege vulnerability in Qualcomm ADSPRPC driver | CVE-2017-0465 | High |
| Elevation of privilege vulnerability in Qualcomm Secure Execution Environment Communicator driver | CVE-2017-0612, CVE-2017-0613, CVE-2017-0614 |
High |
| Elevation of privilege vulnerability in MediaTek power driver | CVE-2017-0615 | High |
| Elevation of privilege vulnerability in MediaTek system management interrupt driver | CVE-2017-0616 | High |
| Elevation of privilege vulnerability in MediaTek video driver | CVE-2017-0617 | High |
| Elevation of privilege vulnerability in MediaTek command queue driver | CVE-2017-0618 | High |
| Elevation of privilege vulnerability in Qualcomm pin controller driver | CVE-2017-0619 | High |
| Elevation of privilege vulnerability in Qualcomm Secure Channel Manager Driver | CVE-2017-0620 | High |
| Elevation of privilege vulnerability in Qualcomm sound codec driver | CVE-2016-5862 | High |
| Elevation of privilege vulnerability in kernel voltage regulator driver | CVE-2014-9940 | High |
| Elevation of privilege vulnerability in Qualcomm camera driver | CVE-2017-0621 | High |
| Elevation of privilege vulnerability in Qualcomm networking driver | CVE-2016-5868 | High |
| Elevation of privilege vulnerability in kernel networking subsystem | CVE-2017-7184 | High |
| Elevation of privilege vulnerability in Goodix touchscreen driver | CVE-2017-0622 | High |
| Elevation of privilege vulnerability in HTC bootloader | CVE-2017-0623 | High |
| Information disclosure vulnerability in Qualcomm Wi-Fi driver | CVE-2017-0624 | High |
| Information disclosure vulnerability in MediaTek command queue driver | CVE-2017-0625 | High |
| Information disclosure vulnerability in Qualcomm crypto engine driver | CVE-2017-0626 | High |
| Denial of service vulnerability in Qualcomm Wi-Fi driver | CVE-2016-10292 | High |
| Information disclosure vulnerability in kernel UVC driver | CVE-2017-0627 | Moderate |
| Information disclosure vulnerability in Qualcomm video driver | CVE-2016-10293 | Moderate |
| Information disclosure vulnerability in Qualcomm power driver (device specific) | CVE-2016-10294 | Moderate |
| Information disclosure vulnerability in Qualcomm LED driver | CVE-2016-10295 | Moderate |
| Information disclosure vulnerability in Qualcomm shared memory driver | CVE-2016-10296 | Moderate |
| Information disclosure vulnerability in Qualcomm camera driver | CVE-2017-0628, CVE-2017-0629 |
Moderate |
| Information disclosure vulnerability in kernel trace subsystem | CVE-2017-0630 | Moderate |
| Information disclosure vulnerability in Qualcomm sound codec driver | CVE-2016-5858 | Moderate |
| Information disclosure vulnerability in Qualcomm camera driver | CVE-2017-0631 | Moderate |
| Information disclosure vulnerability in Qualcomm sound driver | CVE-2016-5347 | Moderate |
| Information disclosure vulnerability in Qualcomm SPCom driver | CVE-2016-5854, CVE-2016-5855 |
Moderate |
| Information disclosure vulnerability in Qualcomm sound codec driver | CVE-2017-0632 | Moderate |
| Information disclosure vulnerability in Broadcom Wi-Fi driver | CVE-2017-0633 | Moderate |
| Information disclosure vulnerability in Synaptics touchscreen driver | CVE-2017-0634 | Moderate |
| Vulnerabilities in Qualcomm components | CVE-2014-9923 (C), CVE-2014-9924 (C), CVE-2014-9925 (C), CVE-2014-9926 (C), CVE-2014-9927 (C), CVE-2014-9928 (C), CVE-2014-9929 (C), CVE-2014-9930 (C), CVE-2015-9005 (C), CVE-2015-9006 (C), CVE-2015-9007 (C), CVE-2016-10297 (C), CVE-2014-9941 (H), CVE-2014-9942 (H), CVE-2014-9943 (H), CVE-2014-9944 (H), CVE-2014-9945 (H), CVE-2014-9946 (H), CVE-2014-9947 (H), CVE-2014-9948 (H), CVE-2014-9949 (H), CVE-2014-9950 (H), CVE-2014-9951 (H), CVE-2014-9952 (H) |
Critical (C)/High (H) |
Samsung & LG
Unterstützte Modelle von Samsung werden in nächster Zeit eine Aktualisierung mit dem Patch vom 1. Mai erhalten. Zusätzlich erweitert der Hersteller das Paket um 11 eigene Patches. Wie immer dürfen auch Besitzer eines Geräts von LG mit einem Sicherheitsupdate rechnen. Diesmal im Paket enthalten sind die Patches vom 1. Mai sowie 3 Extra-Patches von LG.
(Quellen: Android Security Bulletin, Android Police)