PT-2022-6031 · Imagination Technologies+1 · Powervr-Gpu+1

Published

2022-08-24

·

Updated

2022-08-29

·

CVE-2021-39815

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Android SoC versions (affected versions not specified)
Description The issue is related to the PowerVR GPU driver in the Android operating system, which allows unprivileged applications to allocate pinned memory, unpin it, and continue using the page in GPU calls without requiring any privileges. This results in kernel memory corruption. The exploitation of this issue can allow a remote attacker to cause memory damage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-07495
CVE-2021-39815

Affected Products

Android
Powervr-Gpu