CVE-2019-9112

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
25/02/2019
Last modified:
26/02/2019

Description

The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the count argument in _sde_debugfs_conn_cmd_tx_write in drivers/gpu/drm/msm/sde/sde_connector.c. This is exploitable for a device crash via a syscall by a crafted application on a rooted device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:micode:xiaomi_perseus-p-oss:*:*:*:*:*:*:*:* 2018-11-26 (including)


References to Advisories, Solutions, and Tools