In all Android releases from CAF using the Linux kernel, while processing a voice SVC request which is nonstandard by specifying a payload size that will overflow its own declared size, an out of bounds memory copy occurs.
https://www.codeaurora.org/out-bounds-read-when-processing-voice-svc-request-cve-2017-8245