CVE-2017-13166Out-of-bounds Write in INC Android

Severity
7.8HIGHNVD
EPSS
0.1%
top 75.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateMay 13

Description

An elevation of privilege vulnerability in the kernel v4l2 video driver. Product: Android. Versions: Android kernel. Android ID A-34624167.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5google_inc/androidAndroid kernel
Debianlinux/linux_kernel< 4.15.4-1+3

Patches

🔴Vulnerability Details

4
GHSA
GHSA-2pcq-w3mf-59w2: An elevation of privilege vulnerability in the kernel v4l2 video driver2022-05-13
Kernel
Merge tag 'media/v4.17-2' of git://git.kernel.org/pub/scm/linux/kernel/git/mchehab/linux-media2018-04-10
CVEList
CVE-2017-13166: An elevation of privilege vulnerability in the kernel v4l2 video driver2017-12-06
OSV
CVE-2017-13166: An elevation of privilege vulnerability in the kernel v4l2 video driver2017-12-06

📋Vendor Advisories

2
Red Hat
kernel: v4l2: disabled memory access protection mechanism allowing privilege escalation2017-07-20
Debian
CVE-2017-13166: linux - An elevation of privilege vulnerability in the kernel v4l2 video driver. Product...2017

💬Community

2
Bugzilla
CVE-2017-13166 kernel: v4l2: disabled memory access protection mechanism allowing privilege escalation [fedora-all]2018-02-23
Bugzilla
CVE-2017-13166 kernel: v4l2: disabled memory access protection mechanism allowing privilege escalation2018-02-23
CVE-2017-13166 — Out-of-bounds Write in INC Android | cvebase