Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 11 Nov 2016 13:46:47 -0500
From: <cve-assign@...re.org>
To: <idler1984@...il.com>
CC: <cve-assign@...re.org>, <oss-security@...ts.openwall.com>,
	<anarcheuz@...il.com>
Subject: Re: CVE Request - Samsung Exynos fimg2d Multiple Issues

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

> Samsung Exynos fimg2d driver for Android:
> 
> http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016

> SVE-2016-6736: Kernel Crash on /dev/fimg2d ioctl command
> Affected versions: All devices with Exynos 5433/54xx/7420 chipsets
> The fimg2d which is one of the graphic devices for Exynos chipsets
> doesn.t have exception control routines to handle unexpected commands
> and it can lead to kernel panic.
> The patch prevents kernel panic by ignoring inappropriate commands at the state.

Use CVE-2016-9278.


> SVE-2016-6853: Use After Free in /dev/fimg2d
> Affected versions: All devices with Exynos 5433/54xx/7420 chipsets
> A use-after-free vulnerability in fimg2d allows attackers to gain
> access to unauthorized data.
> The patch with error handling was applied.

Use CVE-2016-9279.

- -- 
CVE Assignment Team
M/S M300, 202 Burlington Road, Bedford, MA 01730 USA
[ A PGP key is available for encrypted communications at
  http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJYJhG5AAoJEHb/MwWLVhi23s0P/0n2+8vVYSofET7+hqwCSpWU
6AN45eYz6KoMwMlitjcOC6XYveqTE4L16qQyBPGQJZivKJJjOY+Uv768GUv5dGQB
gtQ8cIEF2o2NdO2FhSwmOz91J7DiLzqU5T7OpixFtELMIGQYJmhR1e8VcgYA4WWn
+MsC1MDIQfCZGaUHX8h9b9ySWkOsQqecJWrRbI6YnAWm2wNZedrUgySOqbYcoi3n
VRZ9XY2B4zRCLXUSrWUwvaeFS1sIf+XK5yhbiF65ZS6h4o2qJg2vHxmn/IXrzZ3V
hXBxXtD8GBi4dG+Xb0HIVDS+SqakGSSJ7wXItLNYSXXT0Zp//SJa/6/fR01JBY54
5/4xVpnjofCssnil7S8ECvAQ8+sYKo3eZbueZbAZzvd0z+w6hpOMFab9bTQCr9IP
Qmc25+xtbRVMhw6Om2k4LfuC2Pu7eOduBpUp9bvSUSmB3tkjoyoND3+PEm/0LWR/
i36ZjShbvHFpQ4oV0mPoZuTeTb1JUfm3GZElzCSLwgL0SQYWjM2gh/7/ClGxEu66
204gBBOzWJW0bmMfpV4AYxqhXu65TmDuEecppmTpeeak43SOerCJAJxvB+Hnng3W
gxsnjPCkGaeCxszyLDAMt44DbVv4Y9KZe9wR9KaVQwrpznBVyRUvHC5jR2nmIcn5
sAjbZqWX9mmuESv5Bk1k
=cN7g
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.