CVE-2017-8260
HIGHQualcomm Android Kernel - Out-of-Bounds Write via Type Downcast Validation Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-8260. PoCs published by ScottyBauer.
AI-analyzed exploit summary This PoC exploits a vulnerability in the Qualcomm MSM camera driver by sending maliciously crafted ioctl commands to trigger a buffer overflow. The code initializes the camera subsystem and then sends a large number of entries to overflow the buffer.
Description
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to a type downcast, a value may improperly pass validation and cause an out of bounds write later.
Exploits (1)
This PoC exploits a vulnerability in the Qualcomm MSM camera driver by sending maliciously crafted ioctl commands to trigger a buffer overflow. The code initializes the camera subsystem and then sends a large number of entries to overflow the buffer.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H