PT-2017-18150 · Google+1 · Android+1

Yonggang Guo

·

Published

2017-11-22

·

Updated

2017-12-11

·

CVE-2017-8141

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions P10 Plus smart phones with software versions earlier than VKY-AL00C00B153
Description The issue concerns a memory double free vulnerability in the Touch Panel driver. An attacker with root privilege of the Android system can trick a user into installing a malicious application. This application can start multiple threads and attempt to free specific memory, potentially triggering a double free condition. This could lead to a system crash or allow for arbitrary code execution.
Recommendations For P10 Plus smart phones with software versions earlier than VKY-AL00C00B153, update to a version VKY-AL00C00B153 or later to resolve the issue. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8141

Affected Products

Android
P10 Plus