CVE-2017-15316
Huawei Mate 9 Pro Mali Double Free Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The GPU driver of Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate 9 Pro Huawei smart phones with software before LON-AL00B 8.0.0.334(C00) has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can call special API, which triggers double free and causes a system crash or arbitrary code execution.
El controlador de unidad de procesamiento gráfico o GPU de los smartphones Mate 9de Huawei con software anterior a MHA-AL00B 8.0.0.334(C00) y Mate 9 Pro de Huawei con software anterior a LON-AL00B 8.0.0.334(C00) contiene una vulnerabilidad de doble liberación (double free) de memoria. Un atacante engaña a un usuario para que instale una aplicación maliciosa que puede llamar a una API especial. Esto desencadena una doble liberación (double free) y provoca el cierre inesperado del sistema o la ejecución de código arbitrario.
This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Huawei Mate 9 Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Mali GPU driver. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the kernel.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-10-14 CVE Reserved
- 2017-12-22 CVE Published
- 2024-08-13 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-415: Double Free
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171201-01-smartphone-en | 2018-01-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Huawei Search vendor "Huawei" | Mate 9 Firmware Search vendor "Huawei" for product "Mate 9 Firmware" | < mha-al00b_8.0.0.334\(c00\) Search vendor "Huawei" for product "Mate 9 Firmware" and version " < mha-al00b_8.0.0.334\(c00\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 9 Search vendor "Huawei" for product "Mate 9" | - | - |
Safe
|
Huawei Search vendor "Huawei" | Mate 9 Pro Firmware Search vendor "Huawei" for product "Mate 9 Pro Firmware" | < lon-al00b_8.0.0.334\(c00\) Search vendor "Huawei" for product "Mate 9 Pro Firmware" and version " < lon-al00b_8.0.0.334\(c00\)" | - |
Affected
| in | Huawei Search vendor "Huawei" | Mate 9 Pro Search vendor "Huawei" for product "Mate 9 Pro" | - | - |
Safe
|