First published: Sun Apr 02 2017(Updated: )
The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an input validation vulnerability, which allows attackers to read and write user-mode memory data anywhere in the TrustZone driver.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P9 Firmware | ||
Huawei P9 Firmware | ||
Huawei P9 Lite Firmware | <=vns-l21c185b130 | |
Huawei P9 Lite Firmware | ||
Huawei P8 Lite Firmware | <=ale-l02c636b150 | |
Huawei P8 Lite Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8764 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive information.
To fix CVE-2016-8764, users should update their Huawei P9, P9 Lite, and P8 Lite devices to the latest recommended software versions.
CVE-2016-8764 affects Huawei P9, P9 Lite, and P8 Lite models running specific older software versions.
CVE-2016-8764 is an input validation vulnerability in the TrustZone driver.
Yes, CVE-2016-8764 could potentially allow attackers to exploit the vulnerability to read and write unauthorized information.