Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie

Android Security Bulletin + Other vulnerabilities!

Options
  • 06-11-2017 11:55pm
    #1
    Registered Users Posts: 7,462 ✭✭✭


    Android Security Bulletin—November 2017

    Pixel / Nexus Security Bulletin—November 2017

    The above bulletins, usually get published on the first Monday (not on a holiday) of the month! They can be found here. (Sometimes posted on a Tuesday, if Monday is a holiday). Usually around 18 Hours GMT.

    The get release around the same time as factory/OTA images for nexus and pixel devices.

    Which also have an additional bulletin available here.

    This month we have the KRACK vulnerability patched.


    The security patches have two levels, and if your finding device/rom is only patching to the first level, then either your device doesn't need the second level patches or the maintainer of the rom/device is just been lazy. This month we have 3 levels, third including the KRACK patch.


    For custom roms patches can take anything from 48 hours to a week to be release to AOSP. So depending on the release schedule of your rom, you may not see the patches until up 2 weeks later.
    Source code patches for these issues will be released to the Android Open Source Project (AOSP) repository in the next 48 hours. We will revise this bulletin with the AOSP links when they are available.


    OEM's are notified a month in advance of these patches, so if you see that patches or at all, depends on the manufacturer of your device.



    Normally I post the security bulletins link's in the Android Version Factory Image thread, but since I no longer have device that get these (nor do I see myself getting a google device in the foreseeable further), hence this thread.



    Other vulnerabilities!

    KRACK and Blueborne are, in my opinion, over hyped security risks. And they where quickly patched in customs roms, such as Lineage OS, before google release the patches this month for the Nexus/Pixel devices. Nexus 6 & 9 support ended last month and probably won't receive the KRACK patch on official rom (has not yet anyway).



    Why this thread?

    Partially surprised a thread like this didn't already exist. Hopefully it can be a catch all thread for security issues and would be more applicable to more than just the factory image threads.

    Please share your thoughts.


«1

Comments

Advertisement