CVE-2019-16508

CWE-190Integer Overflow3 documents3 sources
Severity
7.8HIGH
EPSS
0.1%
top 80.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 1
Latest updateMay 24

Description

The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a malicious application. This occurs because of intentional access for the GPU process to /dev/dri/card1 and the PowerVR ioctl handler, as demonstrated by PVRSRVBridgeSyncPrimOpCreate.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDgoogle/chrome_osr75r75.12105.b+2

🔴Vulnerability Details

2
GHSA
GHSA-7j9g-3hxp-5wwv: The Imagination Technologies driver for Chrome OS before R74-118952022-05-24
CVEList
CVE-2019-16508: The Imagination Technologies driver for Chrome OS before R74-118952019-10-01
CVE-2019-16508 (HIGH CVSS 7.8) | The Imagination Technologies driver | cvebase.io