PT-2017-1610 · Samsung · Samsung Mobile Gpu Driver+1

Published

2017-03-23

·

Updated

2017-03-28

·

CVE-2017-5538

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Samsung Mobile GPU driver versions with M(6.0) and N(7.0) software and Exynos AP chipsets
Description The issue is related to an out-of-bounds read in the kbase dispatch function, located in the arm/t7xx/r5p0/mali kbase core linux.c file of the GPU driver. This could allow attackers to have an unspecified impact via unknown vectors. The vulnerability is associated with a buffer overflow error in memory.
Recommendations For Samsung Mobile GPU driver versions with M(6.0) and N(7.0) software and Exynos AP chipsets, consider disabling the kbase dispatch function as a temporary workaround until a patch is available. Restrict access to the vulnerable GPU driver module to minimize the risk of exploitation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00755
CVE-2017-5538

Affected Products

Exynos Ap
Samsung Mobile Gpu Driver