CVE-2017-13168Incorrect Permission Assignment in INC Android

Severity
7.8HIGHNVD
OSV5.5
EPSS
0.2%
top 61.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 6
Latest updateMay 13

Description

An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5google_inc/androidAndroid kernel
Debianlinux/linux_kernel< 4.17.6-1+3
Ubuntulinux/linux_kernel< 3.13.0-162.212+2

Also affects: Ubuntu Linux 12.04, 14.04, 16.04, 18.04

🔴Vulnerability Details

9
GHSA
GHSA-94xj-6h93-9hj5: An elevation of privilege vulnerability in the kernel scsi driver2022-05-13
OSV
linux-azure vulnerabilities2018-11-14
OSV
linux vulnerabilities2018-11-14
OSV
linux-hwe, linux-azure, linux-gcp vulnerabilities2018-11-14
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oem, linux-raspi2 vulnerabilities2018-11-14

📋Vendor Advisories

9
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2018-11-14
Ubuntu
Linux kernel (Azure) vulnerabilities2018-11-14
Ubuntu
Linux kernel vulnerabilities2018-11-14
Ubuntu
Linux kernel vulnerabilities2018-11-14
Ubuntu
Linux kernel (HWE) vulnerabilities2018-11-14

💬Community

1
Bugzilla
CVE-2017-13168 kernel: scsi: sg driver can improperly access userspace memory2018-12-13
CVE-2017-13168 — Incorrect Permission Assignment | cvebase