Input Validation Flaw in NVIDIA Tegra Gralloc Driver Affecting Android Devices
CVE-2018-6241

7.8HIGH

Key Information:

Vendor
Nvidia
Status
Vendor
CVE Published:
7 January 2019

Summary

A flaw in the NVIDIA Tegra Gralloc module allows for improper validation of input parameters in the registerbuffer API. This loophole can potentially lead to arbitrary code execution, denial of service, or privilege escalation. The vulnerability highlights the importance of securing driver code against unvalidated inputs to prevent exploitation.

Affected Version(s)

Android

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.