Input Validation Flaw in NVIDIA Tegra Gralloc Driver Affecting Android Devices
CVE-2018-6241
7.8HIGH
Summary
A flaw in the NVIDIA Tegra Gralloc module allows for improper validation of input parameters in the registerbuffer API. This loophole can potentially lead to arbitrary code execution, denial of service, or privilege escalation. The vulnerability highlights the importance of securing driver code against unvalidated inputs to prevent exploitation.
Affected Version(s)
Android
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved