CVE-2019-9112: Integer Overflow
The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer overflow and OOPS because of missing checks of the count argument in sdedebugfsconncmdtxwrite in drivers/gpu/drm/msm/sde/sdeconnector.c. This is exploitable for a device crash via a syscall by a crafted application on a rooted device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-9112?
The severity of CVE-2019-9112 is categorized as high with a CVSS score of 7.1.
How do I fix CVE-2019-9112?
To fix CVE-2019-9112, update the msm gpu driver in the specific Linux kernel for Xiaomi devices to the latest version that addresses this vulnerability.
What systems are affected by CVE-2019-9112?
CVE-2019-9112 affects custom Linux kernels on the Xiaomi Perseus-p-oss MIX 3 device.
What type of vulnerability is CVE-2019-9112?
CVE-2019-9112 is classified as an integer overflow vulnerability.
Can CVE-2019-9112 lead to a device crash?
Yes, CVE-2019-9112 is exploitable and can cause the device to crash due to its vulnerability.