CVE-2017-0536
MEDIUMLinux Kernel - Information Disclosure in Synaptics Touchscreen Driver
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-0536. PoCs published by codecat007.
AI-analyzed exploit summary The repository contains a functional proof-of-concept exploit for CVE-2017-0536, a use-after-free vulnerability in the Android kernel's RMI driver. The PoC demonstrates a race condition to leak kernel memory by exploiting improper handling of the `tmpbuf` buffer in the driver.
Description
An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33555878.
Exploits (1)
The repository contains a functional proof-of-concept exploit for CVE-2017-0536, a use-after-free vulnerability in the Android kernel's RMI driver. The PoC demonstrates a race condition to leak kernel memory by exploiting improper handling of the `tmpbuf` buffer in the driver.
References (4)
Scores
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N