CVE-2015-0572
HIGHLinux Kernel 3.0-3.19.8 - Race Condition in ADSPRPC Driver via COMPAT_FASTRPC_IOCTL_INVOKE_FD
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-0572. PoCs published by ScottyBauer.
AI-analyzed exploit summary This PoC exploits a race condition in the Android kernel's fastrpc driver (CVE-2015-0572) by manipulating stack memory during ioctl operations, leading to arbitrary kernel memory corruption. The exploit uses pthreads to race against the ioctl call, overwriting kernel structures with controlled values.
Description
Multiple race conditions in drivers/char/adsprpc.c and drivers/char/adsprpc_compat.c in the ADSPRPC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service (zero-value write) or possibly have unspecified other impact via a COMPAT_FASTRPC_IOCTL_INVOKE_FD ioctl call.
Exploits (1)
This PoC exploits a race condition in the Android kernel's fastrpc driver (CVE-2015-0572) by manipulating stack memory during ioctl operations, leading to arbitrary kernel memory corruption. The exploit uses pthreads to race against the ioctl call, overwriting kernel structures with controlled values.
References (5)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H