CVE-2017-17173

HIGH

Huawei Mate 9 Pro <LON-AL00B 8.0.0.356(C00) - Use After Free

Title source: llm
STIX 2.1

Description

Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.356(C00) has an arbitrary memory free vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to driver to release special kernel memory resource. Successful exploit may result in phone crash or arbitrary code execution.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 28.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
huawei/mate_9_pro_fimware < lon-al00b_8.0.0.356\(c00\)
Published Jun 14, 2018
Tracked Since Feb 18, 2026