Out-of-Bounds Memory Access Vulnerability in Huawei Mate 10 GPU Driver
CVE-2017-17227

7.8HIGH

Key Information:

Vendor

McAfee

Status
Vendor
CVE Published:
9 March 2018

What is CVE-2017-17227?

The GPU driver in Huawei Mate 10 smartphones contains a vulnerability that allows a malicious application to exploit improper input parameter validation. This security flaw enables an attacker to install a rogue application that can invoke the GPU driver with specially crafted parameters, potentially accessing out-of-bounds memory. If successfully executed, this can lead to unexpected crashes or the execution of arbitrary code on the device, compromising its security and functionality.

Affected Version(s)

Mate 10 The versions before ALP-L09 8.0.0.120(C212)

Mate 10 The versions before ALP-L09 8.0.0.127(C900)

Mate 10 The versions before ALP-L09 8.0.0.128(402/C02/C109/C346/C432/C652)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-17227 : Out-of-Bounds Memory Access Vulnerability in Huawei Mate 10 GPU Driver