Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-8717. PoCs published by Google Security Research.
AI-analyzed exploit summary This writeup describes a race condition in the XNU IPComp implementation leading to a double-free vulnerability. The bug is triggered by concurrent processing of IPComp packets on multiple network interfaces, causing memory corruption.
Description
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15, tvOS 13. An application may be able to execute arbitrary code with kernel privileges.
Exploits (1)
This writeup describes a race condition in the XNU IPComp implementation leading to a double-free vulnerability. The bug is triggered by concurrent processing of IPComp packets on multiple network interfaces, causing memory corruption.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H