CVE-2017-17173
HIGHHuawei Mate 9 Pro <LON-AL00B 8.0.0.356(C00) - Use After Free
Title source: llmDescription
Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.356(C00) has an arbitrary memory free vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to driver to release special kernel memory resource. Successful exploit may result in phone crash or arbitrary code execution.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180613-02-smartphone-en
Scores
CVSS v3
7.8
EPSS
0.0011
EPSS Percentile
28.6%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-20
Status
published
Products (1)
huawei/mate_9_pro_fimware
< lon-al00b_8.0.0.356\(c00\)
Published
Jun 14, 2018
Tracked Since
Feb 18, 2026