drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows attackers to gain privileges by leveraging accidental read-write mappings, aka Qualcomm internal bug CR988993.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Android | * | 6.0.1 (including) | |
Linux-flo | Ubuntu | esm-apps/xenial | * |
Linux-flo | Ubuntu | trusty | * |
Linux-flo | Ubuntu | vivid/stable-phone-overlay | * |
Linux-flo | Ubuntu | wily | * |
Linux-flo | Ubuntu | xenial | * |
Linux-flo | Ubuntu | yakkety | * |
Linux-goldfish | Ubuntu | esm-apps/xenial | * |
Linux-goldfish | Ubuntu | trusty | * |
Linux-goldfish | Ubuntu | wily | * |
Linux-goldfish | Ubuntu | xenial | * |
Linux-goldfish | Ubuntu | yakkety | * |
Linux-goldfish | Ubuntu | zesty | * |
Linux-grouper | Ubuntu | trusty | * |
Linux-linaro-omap | Ubuntu | precise | * |
Linux-linaro-shared | Ubuntu | precise | * |
Linux-linaro-vexpress | Ubuntu | precise | * |
Linux-lts-quantal | Ubuntu | precise | * |
Linux-lts-quantal | Ubuntu | precise/esm | * |
Linux-lts-raring | Ubuntu | precise | * |
Linux-lts-raring | Ubuntu | precise/esm | * |
Linux-lts-saucy | Ubuntu | precise | * |
Linux-lts-saucy | Ubuntu | precise/esm | * |
Linux-maguro | Ubuntu | trusty | * |
Linux-mako | Ubuntu | esm-apps/xenial | * |
Linux-mako | Ubuntu | trusty | * |
Linux-mako | Ubuntu | vivid/stable-phone-overlay | * |
Linux-mako | Ubuntu | wily | * |
Linux-mako | Ubuntu | xenial | * |
Linux-mako | Ubuntu | yakkety | * |
Linux-manta | Ubuntu | trusty | * |
Linux-manta | Ubuntu | wily | * |
Linux-qcm-msm | Ubuntu | precise | * |