Vulnerability Description
An elevation of privilege vulnerability in the Direct rendering infrastructure of the NVIDIA Tegra X1 where an unchecked input from userspace is passed as a pointer to kfree. This could lead to kernel memory corruption and possible code execution. This issue is rated as moderate. Product: Pixel. Version: N/A. Android ID: A-38415808. References: N-CVE-2017-0866.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Tegra X1 Firmware | - |
| Nvidia | Tegra X1 | - |
Related Weaknesses (CWE)
References
- https://source.android.com/security/bulletin/pixel/2017-11-01#announcementsIssue TrackingThird Party Advisory
- https://source.android.com/security/bulletin/pixel/2017-11-01#announcementsIssue TrackingThird Party Advisory
FAQ
What is CVE-2017-0866?
CVE-2017-0866 is a vulnerability with a CVSS score of 7.8 (HIGH). An elevation of privilege vulnerability in the Direct rendering infrastructure of the NVIDIA Tegra X1 where an unchecked input from userspace is passed as a pointer to kfree. This could lead to kernel...
How severe is CVE-2017-0866?
CVE-2017-0866 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-0866?
Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Tegra X1 Firmware, Nvidia Tegra X1.