Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-7890. PoCs published by Google Security Research.
AI-analyzed exploit summary The Exynos Seiren Audio driver contains a buffer overflow vulnerability in the write() function due to inadequate bounds checking on user-supplied input. The PoC demonstrates triggering the issue by writing excessive data to /dev/seiren, leading to memory corruption.
Description
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.
Exploits (1)
The Exynos Seiren Audio driver contains a buffer overflow vulnerability in the write() function due to inadequate bounds checking on user-supplied input. The PoC demonstrates triggering the issue by writing excessive data to /dev/seiren, leading to memory corruption.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H