The GPU driver of Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate 9 Pro Huawei smart phones with software before LON-AL00B 8.0.0.334(C00) has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can call special API, which triggers double free and causes a system crash or arbitrary code execution.
References
Link | Resource |
---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171201-01-smartphone-en | Vendor Advisory |
Information
Published : 2017-12-22 09:29
Updated : 2018-01-05 08:00
NVD link : CVE-2017-15316
Mitre link : CVE-2017-15316
JSON object : View
CWE
CWE-415
Double Free
Products Affected
huawei
- mate_9_pro
- mate_9
- mate_9_pro_firmware
- mate_9_firmware