CVE-2017-6292Out-of-bounds Write in Corporation GPU Display Driver

Severity
7.8HIGHNVD
EPSS
0.0%
top 90.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 14

Description

In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due to integer overflow which could lead to local escalation of privilege in the TrustZone with no additional execution privileges needed. User interaction is not needed for exploitation. This issue is rated as high. Version: N/A. Android: A-69480285. Reference: N-CVE-2017-6292.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-xgcp-jrj9-xvpp: In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due to integer overflow which coul2022-05-14
CVEList
CVE-2017-6292: In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due to integer overflow which coul2018-06-07

📋Vendor Advisories

1
Android
CVE-2017-6292: TLZ TrustZone2018-06-01
CVE-2017-6292 — Out-of-bounds Write | cvebase