CVE-2019-16508

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
01/10/2019
Last modified:
08/10/2019

Description

The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a malicious application. This occurs because of intentional access for the GPU process to /dev/dri/card1 and the PowerVR ioctl handler, as demonstrated by PVRSRVBridgeSyncPrimOpCreate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:* r74-11895.b (excluding)
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:* r75 (including) r75.12105.b (excluding)
cpe:2.3:o:google:chrome_os:*:*:*:*:*:*:*:* r76 (including) r76.12208.0.0 (excluding)


References to Advisories, Solutions, and Tools