Executive brief
A vulnerability in the graphics driver of certain Samsung Exynos processors can allow a local user to crash the device. This affects mobile devices using Exynos 5433, 54xx, or 7420 chipsets. An exploit results in a kernel panic, causing the device to restart and leading to a temporary denial of service.
Technical details
The fimg2d graphics driver in Samsung Exynos chipsets (5433, 54xx, and 7420) lacks proper exception control routines to handle unexpected commands sent via ioctl. A local attacker can exploit this improper input validation by sending a crafted ioctl command to /dev/fimg2d. This triggers a kernel panic, resulting in a denial of service. The vulnerability was addressed in the Samsung November 2016 security update by adding checks to ignore inappropriate commands.
Affected products
- Samsung Exynos 5433 chipset
- Samsung Exynos 54xx chipset
- Samsung Exynos 7420 chipset
- Samsung Exynos fimg2d driver
Timeline
- 2016-06-11: disclosed: Reported to Samsung (SVE-2016-6736)
- 2016-11-01: patched: Addressed in Samsung November 2016 Security Maintenance Release
- 2017-01-18: advisory: NVD publication date