Junglewise Threat Intelligence

CVE-2016-6492: MediaTek Linux Driver privilege escalation in camera_fdvt.c

CVE-2016-6492 · Severity: high · CVSS 7.8 · Published 2017-01-12

Technologies: Google Android. Vendors: Google, MediaTek.

Executive brief

A vulnerability in the MediaTek camera driver used in Android devices could allow a malicious application to gain elevated system privileges. By tricking a user into running a specially crafted app, an attacker could bypass security restrictions to access sensitive data or take control of the device. This issue primarily affects the hardware-level communication between the software and the camera component.

Technical details

A privilege escalation vulnerability exists in the MediaTek camera driver (camera_fdvt.c) within the MT6573FDVT_SetRegHW function. The flaw is triggered when a local application issues a specifically crafted MT6573FDVTIOC_T_SET_FDCONF_CMD IOCTL call. This allows an attacker to execute code with elevated kernel-level privileges, potentially leading to a full device compromise. The vulnerability was addressed in the December 2016 Android Security Bulletin, with patches provided for affected MediaTek chipsets. Exploitation requires the attacker to have the ability to run code locally on the device, typically achieved through a malicious application.

Affected products

  • MediaTek Android 7.1.0 and earlier

Timeline

  • 2016-11-07: other: Partners notified of the vulnerability
  • 2016-12-05: patched: Security patch released in Android Security Bulletin
  • 2017-01-12: disclosed: NVD publication date

References

Related threats