Junglewise Threat Intelligence

CVE-2016-9279: Samsung Exynos fimg2d driver use-after-free in Android

CVE-2016-9279 · Severity: high · CVSS 7.5 · Published 2017-01-18

Vendors: Samsung.

Executive brief

A security vulnerability exists in the graphics driver for certain Samsung Exynos processors used in Android devices. This flaw could allow an attacker to access sensitive information that should normally be protected. This impact could lead to the exposure of private user data or system secrets on affected smartphones and tablets.

Technical details

A use-after-free (UAF) vulnerability exists within the fimg2d driver, a 2D graphics accelerator component in Samsung Exynos chipsets (5433, 54xx, and 7420). The vulnerability is located in the handling of the /dev/fimg2d device interface. While the NVD CVSS vector suggests a network attack vector, this class of driver vulnerability typically requires local code execution to interact with the device node. An attacker can exploit this memory corruption flaw to gain unauthorized access to sensitive data or potentially escalate privileges. Samsung addressed this issue in the November 2016 security update (SVE-2016-6853) by improving error handling within the driver.

Affected products

  • Samsung Exynos 5433 chipset
  • Samsung Exynos 54xx chipset
  • Samsung Exynos 7420 chipset
  • Samsung Android

Timeline

  • 2016-08-05: disclosed: Privately reported to Samsung
  • 2016-11-01: patched: Released in Samsung November 2016 security update
  • 2017-01-18: advisory: NVD publication date

References

Related threats