First published: Mon Jul 11 2016(Updated: )
drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows attackers to gain privileges by leveraging accidental read-write mappings, aka Qualcomm internal bug CR988993.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Android | <=6.0.1 | |
Linux kernel | >=3.0<=3.19.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2067 has been classified as a critical vulnerability due to its potential to allow privilege escalation.
To mitigate CVE-2016-2067, users should update their Linux kernel or Android version to the latest patch that addresses this vulnerability.
CVE-2016-2067 affects the Linux kernel version 3.0 up to 3.19.8 and Android versions up to 6.0.1.
CVE-2016-2067 is a privilege escalation vulnerability in the MSM graphics driver utilized in certain Linux and Android platforms.
CVE-2016-2067 was reported as part of the security findings related to Qualcomm Innovation Center's contributions to the Android kernel.