PT-2018-4494 · Google · Android
Published
2018-04-18
·
Updated
2018-05-09
·
CVE-2015-9160
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions prior to 2018-04-05 security patch level
Description
The issue is related to an integer overflow that may occur when large values are passed from the High-Level Operating System (HLOS) in
TZBSP GFX DCVS UPDATE ID, specifically the graphics driver busy time and total time. This affects devices with Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850.Recommendations
Update Android to a version with a security patch level of 2018-04-05 or later to resolve the issue.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android