Lucene search

K
cve[email protected]CVE-2014-0972
HistoryAug 01, 2014 - 11:13 a.m.

CVE-2014-0972

2014-08-0111:13:08
CWE-264
web.nvd.nist.gov
20
kgsl
graphics driver
linux kernel
qualcomm
android
security vulnerability
cve-2014-0972
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The kgsl graphics driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly prevent write access to IOMMU context registers, which allows local users to select a custom page table, and consequently write to arbitrary memory locations, by using a crafted GPU command stream to modify the contents of a certain register.

Affected configurations

NVD
Node
codeauroraandroid-msmMatch3.2.54
OR
codeauroraandroid-msmMatch3.4.72
OR
codeauroraandroid-msmMatch3.4.73
OR
codeauroraandroid-msmMatch3.4.74
OR
codeauroraandroid-msmMatch3.4.75
OR
codeauroraandroid-msmMatch3.4.76
OR
codeauroraandroid-msmMatch3.4.77
OR
codeauroraandroid-msmMatch3.4.78
OR
codeauroraandroid-msmMatch3.4.79
OR
codeauroraandroid-msmMatch3.10
OR
codeauroraandroid-msmMatch3.10.22
OR
codeauroraandroid-msmMatch3.10.23
OR
codeauroraandroid-msmMatch3.10.24
OR
codeauroraandroid-msmMatch3.10.25
OR
codeauroraandroid-msmMatch3.10.26
OR
codeauroraandroid-msmMatch3.10.27
OR
codeauroraandroid-msmMatch3.10.28
OR
codeauroraandroid-msmMatch3.10.29
OR
codeauroraandroid-msmMatch3.12.3
OR
codeauroraandroid-msmMatch3.12.4
OR
codeauroraandroid-msmMatch3.12.5
OR
codeauroraandroid-msmMatch3.12.6
OR
codeauroraandroid-msmMatch3.12.7
OR
codeauroraandroid-msmMatch3.12.8
OR
codeauroraandroid-msmMatch3.12.9
OR
codeauroraandroid-msmMatch3.12.10
OR
codeauroraandroid-msmMatch3.13
OR
codeauroraandroid-msmMatch3.13rc1
OR
codeauroraandroid-msmMatch3.13rc2
OR
codeauroraandroid-msmMatch3.13rc3
OR
codeauroraandroid-msmMatch3.13rc4
OR
codeauroraandroid-msmMatch3.13rc5
OR
codeauroraandroid-msmMatch3.13rc6
OR
codeauroraandroid-msmMatch3.13rc7
OR
codeauroraandroid-msmMatch3.13rc8
OR
codeauroraandroid-msmMatch3.13.1
OR
codeauroraandroid-msmMatch3.13.2
OR
codeauroraandroid-msmMatch3.14rc1
OR
codeauroraandroid-msmMatch3.14rc2

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%