Vulnerability Description
The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a malicious application. This occurs because of intentional access for the GPU process to /dev/dri/card1 and the PowerVR ioctl handler, as demonstrated by PVRSRVBridgeSyncPrimOpCreate.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chrome Os | < r74-11895.b |
Related Weaknesses (CWE)
References
- https://bugs.chromium.org/p/chromium/issues/detail?id=960106ExploitMailing ListVendor Advisory
- https://bugs.chromium.org/p/chromium/issues/detail?id=960106ExploitMailing ListVendor Advisory
FAQ
What is CVE-2019-16508?
CVE-2019-16508 is a vulnerability with a CVSS score of 7.8 (HIGH). The Imagination Technologies driver for Chrome OS before R74-11895.B, R75 before R75-12105.B, and R76 before R76-12208.0.0 allows attackers to trigger an Integer Overflow and gain privileges via a mal...
How severe is CVE-2019-16508?
CVE-2019-16508 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16508?
Check the references section above for vendor advisories and patch information. Affected products include: Google Chrome Os.