First published: Tue Oct 01 2019(Updated: )
The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a malicious application. This occurs because of intentional access for the GPU process to /dev/dri/card1 and the PowerVR ioctl handler, as demonstrated by PVRSRVBridgeSyncPrimOpCreate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome OS | <r74-11895.b | |
Google Chrome OS | >=r75<r75.12105.b | |
Google Chrome OS | >=r76<r76.12208.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-16508.
The affected software is Google Chrome OS versions r74-11895.b, r75-12105.b, and r76-12208.0.0.
The severity of CVE-2019-16508 is critical with a severity value of 7.8.
Attackers can exploit CVE-2019-16508 by triggering an Integer Overflow and gaining privileges through a malicious application.
To fix CVE-2019-16508, update Google Chrome OS to the latest versions available: r74-11895.b, r75-12105.b, and r76-12208.0.0.