Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-0516. PoCs published by ScottyBauer.
AI-analyzed exploit summary The PoC exploits CVE-2017-0516 by sending malformed ioctl requests to the /dev/hbtp_input device, causing a denial-of-service (DoS) condition due to improper bounds checking in the kernel driver. The code continuously sends crafted hbtp_input_absinfo structures with invalid values to trigger the vulnerability.
Description
An elevation of privilege vulnerability in the Qualcomm input hardware driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32341680. References: QC-CR#1096301.
Exploits (1)
The PoC exploits CVE-2017-0516 by sending malformed ioctl requests to the /dev/hbtp_input device, causing a denial-of-service (DoS) condition due to improper bounds checking in the kernel driver. The code continuously sends crafted hbtp_input_absinfo structures with invalid values to trigger the vulnerability.
References (4)
Scores
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H