| <html devsite><head> |
| <title>Pixel/Nexus 安全性公告 - 2018 年 4 月</title> |
| <meta name="project_path" value="/_project.yaml"/> |
| <meta name="book_path" value="/_book.yaml"/> |
| </head> |
| <body> |
| <!-- |
| Copyright 2018 The Android Open Source Project |
| |
| Licensed under the Apache License, Version 2.0 (the "License"); |
| you may not use this file except in compliance with the License. |
| You may obtain a copy of the License at |
| |
| //www.apache.org/licenses/LICENSE-2.0 |
| |
| Unless required by applicable law or agreed to in writing, software |
| distributed under the License is distributed on an "AS IS" BASIS, |
| WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| See the License for the specific language governing permissions and |
| limitations under the License. |
| --> |
| |
| <p><em>發佈日期:2018 年 4 月 2 日 | 更新日期:2018 年 4 月 10 日</em></p> |
| |
| <p> |
| Pixel/Nexus 安全性公告列舉對<a href="https://support.google.com/pixelphone/answer/4457705#pixel_phones&nexus_devices">支援的 Google Pixel 和 Nexus 裝置</a> (Google 裝置) 造成影響的安全性漏洞和功能改善項目,並說明各項相關細節。2018-04-05 之後的安全性修補程式等級也已針對 Google 裝置解決了這個公告和 <a href="/security/bulletin/2018-04-01">2018 年 4 月 Android 安全性公告</a>列出的所有問題。請參閱<a href="https://support.google.com/pixelphone/answer/4457705">檢查及更新 Android 版本</a>一文,瞭解如何查看裝置的安全性修補程式等級。</p> |
| <p> |
| 所有支援的 Google 裝置都會收到 2018-04-05 修補程式等級更新。我們建議所有客戶接受這些裝置更新。 |
| </p> |
| <p class="note"> |
| <strong>注意:</strong>您可以前往 <a href="https://developers.google.com/android/nexus/images">Google Developers 網站</a>取得 Google 裝置韌體映像檔。 |
| </p> |
| |
| <h2 id="announcements">公告事項</h2> |
| <p>我們除了修補 <a href="/security/bulletin/2018-04-01">2018 年 4 月 Android 安全性公告</a>中所列出的安全性漏洞外,也針對下文列出的 Google 裝置的安全性漏洞提供修補程式。我們的合作夥伴至少會提前一個月收到這些問題的相關通知,方便他們將相關內容納入其裝置更新中。</p> |
| |
| <h2 id="security-patches">安全性修補程式</h2> |
| <p> |
| 我們依照資安問題本身所影響的元件將各項漏洞分門別類,另外也附上了問題說明和一份 CVE 資訊表,其中包括了相關參考資料、<a href="#type">漏洞類型</a>、<a href="https://source.android.com/security/overview/updates-resources.html#severity">嚴重程度</a>,以及更新的 Android 開放原始碼計劃 (AOSP) 版本 (在適用情況下)。假如相關錯誤有公開變更,該錯誤 ID 會連結到相對應的變更 (例如 Android 開放原始碼計劃變更清單)。如果單一錯誤有多項相關變更,您可以透過該錯誤 ID 後面的編號連結開啟額外的參考資料。</p> |
| |
| <h3 id="framework">架構</h3> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>參考資料</th> |
| <th>類型</th> |
| <th>嚴重程度</th> |
| <th>更新的 Android 開放原始碼計劃版本</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13294</td> |
| <td><a href="https://android.googlesource.com/platform/packages/apps/Email/+/c3e0aba2a604ce7c3807d65df1e6a2b848287019">A-71814449</a> |
| [<a href="https://android.googlesource.com/platform/packages/apps/UnifiedEmail/+/e00598532bbfc8618b7c051cbf6bd15491f61f27">2</a>]</td> |
| <td>ID</td> |
| <td>中</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13295</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/base/+/a2a36541f0b3603335e74da0a8d2b6a9d5bcec3f">A-62537081</a></td> |
| <td>DoS</td> |
| <td>中</td> |
| <td>6.0、6.0.1、7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="media-framework">媒體架構</h3> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>參考資料</th> |
| <th>類型</th> |
| <th>嚴重程度</th> |
| <th>更新的 Android 開放原始碼計劃版本</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13300</td> |
| <td>A-71567394<a href="#asterisk">*</a></td> |
| <td>DoS</td> |
| <td>高</td> |
| <td>6.0、6.0.1</td> |
| </tr> |
| <tr> |
| <td rowspan="2">CVE-2017-13296</td> |
| <td rowspan="2"><a href="https://android.googlesource.com/platform/external/libavc/+/3e3e81ede5229c5a9c6b7bf6a63844ecf07ae3ae">A-70897454</a></td> |
| <td>ID</td> |
| <td>中</td> |
| <td>7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>DoS</td> |
| <td>高</td> |
| <td>6.0、6.0.1</td> |
| </tr> |
| <tr> |
| <td rowspan="2">CVE-2017-13297</td> |
| <td rowspan="2"><a href="https://android.googlesource.com/platform/external/libhevc/+/daaece3e79db33f6c473bb54a39933d387a9bf95">A-71766721</a></td> |
| <td>ID</td> |
| <td>中</td> |
| <td>7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>DoS</td> |
| <td>高</td> |
| <td>6.0、6.0.1</td> |
| </tr> |
| <tr> |
| <td rowspan="2">CVE-2017-13298</td> |
| <td rowspan="2"><a href="https://android.googlesource.com/platform/frameworks/av/+/12e25a753f4b6f0aa935e54bae66023bd8321598">A-72117051</a></td> |
| <td>ID</td> |
| <td>中</td> |
| <td>7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>DoS</td> |
| <td>高</td> |
| <td>6.0、6.0.1</td> |
| </tr> |
| <tr> |
| <td rowspan="2">CVE-2017-13299</td> |
| <td rowspan="2"><a href="https://android.googlesource.com/platform/external/libavc/+/d849abf312a365553ce68aec32dea93230036abe">A-70897394</a></td> |
| <td>NSI</td> |
| <td>NSI</td> |
| <td>7.0、7.1.1、7.1.2、8.0、8.1</td> |
| </tr> |
| <tr> |
| <td>DoS</td> |
| <td>高</td> |
| <td>6.0、6.0.1</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="system">系統</h3> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>參考資料</th> |
| <th>類型</th> |
| <th>嚴重程度</th> |
| <th>更新的 Android 開放原始碼計劃版本</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13301</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/base/+/384689934d293acf532e3fea3e72ef78df4f2d1e">A-66498711</a> |
| [<a href="https://android.googlesource.com/platform/frameworks/base/+/d52b215f82e464705373d794748325298f0a1f9a">2</a>]</td> |
| <td>DoS</td> |
| <td>中</td> |
| <td>8.0</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13302</td> |
| <td><a href="https://android.googlesource.com/platform/frameworks/base/+/e54ad58aea33860fbb36bf828684e3df6393f602">A-69969749</a></td> |
| <td>DoS</td> |
| <td>中</td> |
| <td>8.0</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="broadcom-components">Broadcom 元件</h3> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>參考資料</th> |
| <th>類型</th> |
| <th>嚴重程度</th> |
| <th>元件</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13303</td> |
| <td>A-71359108<a href="#asterisk">*</a><br /> |
| B-V2018010501</td> |
| <td>ID</td> |
| <td>中</td> |
| <td>bcmdhd 驅動程式</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="kernel-components">核心元件</h3> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="19%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="39%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>參考資料</th> |
| <th>類型</th> |
| <th>嚴重程度</th> |
| <th>元件</th> |
| </tr> |
| <tr> |
| <td>CVE-2017-13304</td> |
| <td>A-70576999<a href="#asterisk">*</a></td> |
| <td>ID</td> |
| <td>中</td> |
| <td>mnh_sm 驅動程式</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13305</td> |
| <td>A-70526974<a href="#asterisk">*</a></td> |
| <td>ID</td> |
| <td>中</td> |
| <td>encrypted-keys</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-17449</td> |
| <td>A-70980949<br /> |
| <a href="https://lkml.org/lkml/2017/12/5/950">上游程式庫核心</a></td> |
| <td>ID</td> |
| <td>中</td> |
| <td>netlink tap</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13306</td> |
| <td>A-70295063<a href="#asterisk">*</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>mnh 驅動程式</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-13307</td> |
| <td>A-69128924<a href="#asterisk">*</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>pci sysfs</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-17712</td> |
| <td>A-71500434<br /> |
| <a href="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8f659a03a0ba9289b9aeb9b4470e6fb263d6f483"> |
| 上游程式庫核心</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>網路 ipv4</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-15115</td> |
| <td>A-70217214<br /> |
| <a href="http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=df80cd9b28b9ebaa284a41df611dbf3a2d05ca74"> |
| 上游程式庫核心</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>SCTP</td> |
| </tr> |
| </tbody></table> |
| |
| <h3 id="qualcomm-components">Qualcomm 元件</h3> |
| |
| <table> |
| <colgroup><col width="17%" /> |
| <col width="25%" /> |
| <col width="9%" /> |
| <col width="14%" /> |
| <col width="33%" /> |
| </colgroup><tbody><tr> |
| <th>CVE</th> |
| <th>參考資料</th> |
| <th>類型</th> |
| <th>嚴重程度</th> |
| <th>元件</th> |
| </tr> |
| <tr> |
| <td>CVE-2018-3598</td> |
| <td>A-71501698<br /> |
| <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=bfd8ffc65e6e82de2adceba58bd67137fb3b2024"> |
| QC-CR#1097390</a></td> |
| <td>ID</td> |
| <td>中</td> |
| <td>camera_v2 驅動程式</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-5826</td> |
| <td>A-69128800<a href="#asterisk">*</a><br /> |
| QC-CR#2157283</td> |
| <td>ID</td> |
| <td>中</td> |
| <td>qcacld-3.0 hdd 驅動程式</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-15853</td> |
| <td>A-65853393<a href="#asterisk">*</a><br /> |
| QC-CR#2116517<br /> |
| QC-CR#2125577</td> |
| <td>ID</td> |
| <td>中</td> |
| <td>WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3584</td> |
| <td>A-64610600<a href="#asterisk">*</a><br /> |
| QC-CR#2142046</td> |
| <td>ID</td> |
| <td>中</td> |
| <td>rmnet_usb</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-8269</td> |
| <td>A-33967002<a href="#asterisk">*</a><br /> |
| QC-CR#2013145<br /> |
| QC-CR#2114278</td> |
| <td>ID</td> |
| <td>中</td> |
| <td>IPA 驅動程式</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-15837</td> |
| <td>A-64403015<a href="#asterisk">*</a><br /> |
| QC-CR#2116387</td> |
| <td>ID</td> |
| <td>中</td> |
| <td>NL80211 驅動程式</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-5823</td> |
| <td>A-72957335<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=fc5bbedd4ab9fd5239be8618afe714d39dd8de49"> |
| QC-CR#2139436</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-5825</td> |
| <td>A-72957269<br /> |
| <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=5ae227670444cf8ea7b8a8d98eab41404a03332f">QC-CR#2151146</a> |
| [<a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=cf0f031ffbb6a8e08e517f653045c3f81d7f2663">2</a>] |
| [<a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=09a34b7878a732187f9138900667d8abb2b1c39c">3</a>]</td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>IPA 驅動程式</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-5824</td> |
| <td>A-72957235<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=b34f6f3afe229e32a32418f75889279f6e00d157">QC-CR#2149399</a> |
| [<a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=d3a92a1656a3ee2fc44d4ff98614a4f5b70f1893">2</a>]</td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-5827</td> |
| <td>A-72956920<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=53e6d889ac29336ba212a0d4a987455a85736fa8"> |
| QC-CR#2161977</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-5822</td> |
| <td>A-71501692<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=edc42ce371b6831dc55a15bc2624175bd538aa37"> |
| QC-CR#2115221</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>QC WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-5821</td> |
| <td>A-71501687<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=08ab943766abe845a8fae21689bae18dd74e9b20"> |
| QC-CR#2114363</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>數據機驅動程式</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-5820</td> |
| <td>A-71501686<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=a4a8475ea650c16705a3eaa011524820dc5ffd44"> |
| QC-CR#2114336</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>數據機驅動程式</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3599</td> |
| <td>A-71501666<br /> |
| <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=cf2702c1a77d2a164a3be03597eff7e6fe5f967e"> |
| QC-CR#2047235</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>Qualcomm 核心服務</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3596</td> |
| <td>A-35263529<a href="#asterisk">*</a><br /> |
| QC-CR#640898</td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3568</td> |
| <td>A-72957136<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=70cd30a5c1fdd02af19cf0e34c41842cce89a82d"> |
| QC-CR#2152824</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-3567</td> |
| <td>A-72956997<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=f2627fca43bc4403a445c2b84481383ac0249364">QC-CR#2147119</a> |
| [<a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=25c131e8a807894e04f95bdeb1cbd0376eda3bea">2</a>]</td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-15855</td> |
| <td>A-72957336<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=75c0ea8622bb07716d2a82247e6dd1597980f223"> |
| QC-CR#2149501</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2018-5828</td> |
| <td>A-71501691<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-2.0/commit/?id=6299a6bf166a60a47e9108ae2119027e787432d0"> |
| QC-CR#2115207</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>QC WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-15836</td> |
| <td>A-71501693<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=058e1eef2b1422bc0dd70f73832f1ac8a3dbe806"> |
| QC-CR#2119887</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>QC WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-14890</td> |
| <td>A-71501695<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=234e14add09a1ba4a1b1d81d474ac3978dc94fd6"> |
| QC-CR#2120751</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>QC WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-14894</td> |
| <td>A-71501694<br /> |
| <a href="https://source.codeaurora.org/quic/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0/commit/?id=dfca3d8173c1548a97e558cb8abd1ffd2483f8b7"> |
| QC-CR#2120424</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>QC WLAN</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-14880</td> |
| <td>A-68992477<br /> |
| <a href="https://source.codeaurora.org/quic/la/kernel/msm-3.18/commit/?id=cbf3702ae1c5e2cacd6f15a5eb7a799e2f1ed96f"> |
| QC-CR#2078734</a> |
| [<a href="https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=d72e444dce0b9d20fdcdc4daeb6227e3536eebf7">2</a>]</td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>IPA WAN 驅動程式</td> |
| </tr> |
| <tr> |
| <td>CVE-2017-11075</td> |
| <td>A-70237705<br /> |
| <a href="https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?id=7a07165c62926e899b710e1fed31532f31797dd5"> |
| QC-CR#2098332</a></td> |
| <td>EoP</td> |
| <td>中</td> |
| <td>音訊 DSP 驅動程式</td> |
| </tr> |
| </tbody></table> |
| |
| <h2 id="functional-updates">功能更新</h2> |
| <p> |
| 這些更新的目的在於解決受影響 Pixel 裝置的功能問題,與 Pixel 裝置的安全性無關。下表列出相關參考資料、受影響的類別 (例如藍牙或行動數據)、改善項目,以及受影響的裝置。 |
| </p> |
| |
| <table> |
| <tbody><tr> |
| <th>參考資料</th> |
| <th>類別</th> |
| <th>改善項目</th> |
| <th>裝置</th> |
| </tr> |
| <tr> |
| <td>A-35963245</td> |
| <td>效能</td> |
| <td>支援輔助撥號功能</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-37681923<br /> |
| A-68215016</td> |
| <td>記錄</td> |
| <td>改善異常檢測指標</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-63908720</td> |
| <td>記錄</td> |
| <td>改善 diskstats 記錄功能</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-64101451</td> |
| <td>效能</td> |
| <td>改善使用特定電信業者撥打緊急電話時,從 VoLTE 轉換至 VoWi-Fi 的效能</td> |
| <td>Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-64586126</td> |
| <td>相機</td> |
| <td>提升 Google 相機的微影片拍攝效能</td> |
| <td>Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-64610438</td> |
| <td>效能</td> |
| <td>降低開啟特定應用程式時的延遲</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-65175134</td> |
| <td>視訊</td> |
| <td>改善特定影片串流的解碼效能</td> |
| <td>Pixel、Pixel XL</td> |
| </tr> |
| <tr> |
| <td>A-65347520</td> |
| <td>效能</td> |
| <td>降低特定情況下的指紋辨識和鍵盤延遲</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-65490850</td> |
| <td>UI</td> |
| <td>調整在進行視訊通話時進入或離開 Wi-Fi 覆蓋範圍的通知</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-65509134</td> |
| <td>網路連線</td> |
| <td>在特定網路上啟用 IMS911</td> |
| <td>Pixel 2、Pixel 2 XL、Pixel、Pixel XL</td> |
| </tr> |
| <tr> |
| <td>A-66951771</td> |
| <td>記錄</td> |
| <td>偵測開發人員的 Wi-Fi Passpoint 統計資料</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-66957450</td> |
| <td>效能</td> |
| <td>提升螢幕鎖定的效能</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-67094673</td> |
| <td>記錄</td> |
| <td>改善開始時間記錄功能</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-67589241</td> |
| <td>效能</td> |
| <td>改善 Pixel 2/Pixel 2 XL 的磁力感測器效能</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-67593274</td> |
| <td>電池</td> |
| <td>減少因數據機問題而產生的耗電情況</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-67634615</td> |
| <td>穩定性</td> |
| <td>改善 Pixel 和 Pixel 2 手機上的數據機穩定性</td> |
| <td>Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-67750231</td> |
| <td>UI</td> |
| <td>調整來電轉接 UI</td> |
| <td>Nexus 5X、Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-67774904</td> |
| <td>網路連線</td> |
| <td>改善透過 Wi-Fi 連線進行多方通話時的效能</td> |
| <td>Pixel、Pixel XL</td> |
| </tr> |
| <tr> |
| <td>A-67777512</td> |
| <td>網路連線</td> |
| <td>改善澳洲部分地區的 T-Mobile 使用者的數據連線品質</td> |
| <td>Pixel、Pixel XL</td> |
| </tr> |
| <tr> |
| <td>A-67882977</td> |
| <td>憑證</td> |
| <td>更新憑證</td> |
| <td>Pixel、Pixel XL</td> |
| </tr> |
| <tr> |
| <td>A-68150449<br /> |
| A-68059359<br /> |
| A-69797741<br /> |
| A-69378640<br /> |
| A-68824279</td> |
| <td>穩定性</td> |
| <td>提升 Pixel 2 手機的 Wi-Fi 連線穩定性</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-68217064</td> |
| <td>效能</td> |
| <td>改善在訊號強度低的地區轉換至 Wi-Fi 通話時的效能</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-68398312</td> |
| <td>效能</td> |
| <td>改善透過 Wi-Fi 連線進行電話會議時的效能</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-68671462</td> |
| <td>網路連線</td> |
| <td>改善部分電信業者的 VoLTE 效能</td> |
| <td>Nexus 5X、Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-68841424</td> |
| <td>網路連線</td> |
| <td>調整 APN 更新行為</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-68863351</td> |
| <td>UI</td> |
| <td>更新「設定」應用程式圖示</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-68923696<br /> |
| A-68922470<br /> |
| A-68940490</td> |
| <td>憑證</td> |
| <td>升級憑證以避免服務中斷</td> |
| <td>Nexus 5X、Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-68931709</td> |
| <td>開發人員</td> |
| <td>新增開發人員適用的 PeerHandle API 方法</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-68959671</td> |
| <td>網路連線</td> |
| <td>更新 Pixel 手機的 Verizon 服務 APK</td> |
| <td>Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-69003183</td> |
| <td>記錄</td> |
| <td>改善 Wi-Fi 和 RPM 記錄功能</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-69017578<br /> |
| A-68138080<br /> |
| A-68205105<br /> |
| A-70731000<br /> |
| A-69574837<br /> |
| A-68474108<br /> |
| A-70406781</td> |
| <td>網路連線、效能</td> |
| <td>提升使用特定電信業者網路的連線品質和效能</td> |
| <td>Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-69064494</td> |
| <td>效能</td> |
| <td>改善通知監聽應用程式的效能</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-69152057</td> |
| <td>網路連線</td> |
| <td>解決來電轉接問題</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-69209000</td> |
| <td>網路連線</td> |
| <td>提升 Pixel 2 連線到特定 Wi-Fi 網路時的網際網路連線品質</td> |
| <td>Pixel 2</td> |
| </tr> |
| <tr> |
| <td>A-69238007<br /> |
| A-68202289<br /> |
| A-69334308</td> |
| <td>網路連線</td> |
| <td>調整 APN 設定</td> |
| <td>Nexus 5X、Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-69261367<br /> |
| A-70512352</td> |
| <td>簡訊</td> |
| <td>改善特定電信業者的多媒體訊息傳送效能</td> |
| <td>Nexus 5X、Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-69275204</td> |
| <td>電池</td> |
| <td>調整電池記憶容量的增量上限和減量下限</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-69334266</td> |
| <td>網路連線</td> |
| <td>將特定電信業者的語音領域變更為電路交換領域</td> |
| <td>Pixel XL</td> |
| </tr> |
| <tr> |
| <td>A-69475609</td> |
| <td>效能</td> |
| <td>調整「電話」應用程式的逾時設定</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-69672417</td> |
| <td>穩定性</td> |
| <td>提升加拿大特定地區的 Pixel 2 裝置穩定性</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-69848394<br /> |
| A-68275646</td> |
| <td>效能</td> |
| <td>改善免安裝應用程式的效能</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-69870527</td> |
| <td>UI</td> |
| <td>改善緊急電話連線的指標</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-70045970</td> |
| <td>電池</td> |
| <td>最佳化搜尋邏輯以提升電池效能</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-70094083<br /> |
| A-70094701</td> |
| <td>電池</td> |
| <td>改善 Pixel 2 和 Pixel 2 XL 的電池記錄功能</td> |
| <td>Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-70214869</td> |
| <td>GPS</td> |
| <td>改善 Pixel 2 XL 的 GPS 時間效能</td> |
| <td>Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-70338906</td> |
| <td>音訊</td> |
| <td>改善通話時的喇叭效能</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-70398372</td> |
| <td>UI</td> |
| <td>調整 Verizon 的進階通話設定</td> |
| <td>Nexus 5X、Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-70576351</td> |
| <td>網路連線</td> |
| <td>變更為優先使用特定頻帶</td> |
| <td>Nexus 5X、Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-70580873<br /> |
| A-70912923<br /> |
| A-71497259</td> |
| <td>網路連線</td> |
| <td>改善部分電信業者的通話效能</td> |
| <td>Pixel、Pixel XL、Pixel 2、Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-70815434</td> |
| <td>網路連線</td> |
| <td>改善電信業者 Simyo 的網路效能</td> |
| <td>Nexus 5X</td> |
| </tr> |
| <tr> |
| <td>A-71708302</td> |
| <td>記錄</td> |
| <td>改善連線指標</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-71983424</td> |
| <td>效能</td> |
| <td>提升切換 LTE 和 Wi-Fi 時的服務品質</td> |
| <td>Pixel 2 XL</td> |
| </tr> |
| <tr> |
| <td>A-72119809</td> |
| <td>網路連線</td> |
| <td>改善裝置在使用特定 SIM 卡時的數據效能</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-72175011</td> |
| <td>記錄</td> |
| <td>改善自動填入記錄功能</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-72797728<br /> |
| A-71599119</td> |
| <td>記錄</td> |
| <td>改善內部疑難排解工具</td> |
| <td>全部</td> |
| </tr> |
| <tr> |
| <td>A-72871435</td> |
| <td>記錄</td> |
| <td>改善同時啟用 VPN 和 Wi-Fi 時的網路效能</td> |
| <td>全部</td> |
| </tr> |
| </tbody></table> |
| |
| <h2 id="common-questions-and-answers">常見問題與解答</h2> |
| <p> |
| 如果您在閱讀這篇公告後有任何疑問,可參考本節的常見問答。 |
| </p> |
| <p> |
| <strong>1. 如何判斷我目前的裝置軟體版本是否已修正這些問題? |
| </strong> |
| </p> |
| <p> |
| 2018-04-05 之後的安全性修補程式等級已解決了所有與 2018-04-05 安全性修補程式等級及所有先前修補程式等級相關的問題。請參閱 <a href="https://support.google.com/pixelphone/answer/4457705#pixel_phones&nexus_devices">Pixel 與 Nexus 更新時間表</a>中的操作說明,瞭解如何查看裝置的安全性修補程式等級。 |
| </p> |
| <p id="type"> |
| <strong>2.「類型」<em></em>欄中的項目代表什麼意義?</strong> |
| </p> |
| <p> |
| 在資安漏洞詳情表格中,「類型」<em></em>欄中的項目代表的是安全性漏洞的類別。 |
| </p> |
| <table> |
| <colgroup><col width="25%" /> |
| <col width="75%" /> |
| </colgroup><tbody><tr> |
| <th>縮寫</th> |
| <th>定義</th> |
| </tr> |
| <tr> |
| <td>RCE</td> |
| <td>遠端程式碼執行</td> |
| </tr> |
| <tr> |
| <td>EoP</td> |
| <td>權限升級</td> |
| </tr> |
| <tr> |
| <td>ID</td> |
| <td>資訊外洩</td> |
| </tr> |
| <tr> |
| <td>DoS</td> |
| <td>阻斷服務</td> |
| </tr> |
| <tr> |
| <td>無</td> |
| <td>未分類</td> |
| </tr> |
| </tbody></table> |
| <p> |
| <strong>3.「參考資料」<em></em>欄底下列出的識別碼代表什麼意義?</strong> |
| </p> |
| <p> |
| 資安漏洞詳情表格中「參考資料」<em></em>欄底下的項目可能會包含一個前置字串,用以表示該參考資料值所屬的機構或公司。 |
| </p> |
| <table> |
| <colgroup><col width="25%" /> |
| <col width="75%" /> |
| </colgroup><tbody><tr> |
| <th>前置字串</th> |
| <th>參考資料</th> |
| </tr> |
| <tr> |
| <td>A-</td> |
| <td>Android 錯誤 ID</td> |
| </tr> |
| <tr> |
| <td>QC-</td> |
| <td>Qualcomm 參考編號</td> |
| </tr> |
| <tr> |
| <td>M-</td> |
| <td>MediaTek 參考編號</td> |
| </tr> |
| <tr> |
| <td>N-</td> |
| <td>NVIDIA 參考編號</td> |
| </tr> |
| <tr> |
| <td>B-</td> |
| <td>Broadcom 參考編號</td> |
| </tr> |
| </tbody></table> |
| <p id="asterisk"> |
| <strong>4.「參考資料」<em></em>欄中 Android 錯誤 ID 旁邊的星號 (*) 代表什麼意義?</strong> |
| </p> |
| <p> |
| 在「參考資料」<em></em>欄中的 Android 錯誤 ID 旁邊標上星號 (*) 代表該問題並未公開,相關的更新通常是直接整合在最新的 Nexus 裝置專用驅動程式的安裝檔中。您可以前往 <a href="https://developers.google.com/android/nexus/drivers">Google Developers 網站</a>下載這些驅動程式。 |
| </p> |
| <p> |
| <strong>5. 為什麼安全性漏洞會分別刊載在這份安全性公告和 Android 安全性公告?</strong> |
| </p> |
| <p> |
| 為了宣告 Android 裝置最新的安全性修補程式等級,我們必須先在 Android 安全性公告中刊載相關的安全性漏洞。其他安全性漏洞 (例如本安全性公告所刊載的安全性漏洞) 並未強制規定宣告安全性修補程式等級。 |
| </p> |
| <h2 id="versions">版本</h2> |
| <table> |
| <colgroup><col width="25%" /> |
| <col width="25%" /> |
| <col width="50%" /> |
| </colgroup><tbody><tr> |
| <th>版本</th> |
| <th>日期</th> |
| <th>附註</th> |
| </tr> |
| <tr> |
| <td>1.0</td> |
| <td>2018 年 4 月 2 日</td> |
| <td>發佈公告。</td> |
| </tr> |
| <tr> |
| <td>1.1</td> |
| <td>2018 年 4 月 4 日</td> |
| <td>修訂公告內容 (加入 Android 開放原始碼計劃連結)。</td> |
| </tr> |
| <tr> |
| <td>1.2</td> |
| <td>2018 年 4 月 10 日</td> |
| <td>修訂公告內容 (更新 A-72871435 的說明)。</td> |
| </tr> |
| </tbody></table> |
| |
| </body></html> |