In libavc there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Reference: https://source.android.com/security/bulletin/android-10
Created libavc1394 tracking bugs for this issue: Affects: fedora-all [bug 1824443]