CVE-2017-0576
HIGHLinux Kernel - Integer Overflow in Qualcomm Crypto Engine Driver
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-0576. PoCs published by derrekr.
AI-analyzed exploit summary This PoC exploits a byte offset overflow vulnerability in the Qualcomm Crypto Engine driver (qce) by crafting a malicious ioctl request with manipulated buffer lengths and offsets, leading to memory corruption. The exploit targets the /dev/qce device and uses a multi-threaded approach to trigger the vulnerability.
Description
An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33544431. References: QC-CR#1103089.
Exploits (1)
This PoC exploits a byte offset overflow vulnerability in the Qualcomm Crypto Engine driver (qce) by crafting a malicious ioctl request with manipulated buffer lengths and offsets, leading to memory corruption. The exploit targets the /dev/qce device and uses a multi-threaded approach to trigger the vulnerability.
References (4)
Scores
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H