CVE-2017-6290Integer Overflow or Wraparound in Corporation GPU Display Driver

Severity
7.8HIGHNVD
EPSS
0.0%
top 90.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 14

Description

In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due to an integer overflow which could lead to local escalation of privilege with no additional execution privileges needed. User interaction not needed for exploitation. This issue is rated as high. Version: N/A. Android: A-69559414. Reference: N-CVE-2017-6290.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-92f6-f29p-ggfm: In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due to an integer overflow which c2022-05-14
CVEList
CVE-2017-6290: In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due to an integer overflow which c2018-06-07

📋Vendor Advisories

1
Android
CVE-2017-6290: TLK TrustZone2018-06-01
CVE-2017-6290 — Integer Overflow or Wraparound | cvebase