Overview
- Description
- Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 6.9
- Impact score
- 10
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:C/I:C/A:C
Known exploits
Data from CISA
- Vulnerability name
- Linux Kernel Integer Overflow Vulnerability
- Exploit added on
- Sep 15, 2022
- Exploit action due
- Oct 6, 2022
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-190
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F6BFD971-9FC9-4D37-99FC-9E39178942E2", "versionEndExcluding": "3.0.75", "versionStartIncluding": "2.6.12" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "88DA168C-393B-4853-8034-6E9099CC9623", "versionEndExcluding": "3.2.45", "versionStartIncluding": "3.1" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8FECB4AF-F9DF-44E3-BD62-741D5D129053", "versionEndExcluding": "3.4.42", "versionStartIncluding": "3.3" }, { "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E3C2571-AFE5-4ED0-810D-232092DD0220", "versionEndExcluding": "3.8.9", "versionStartIncluding": "3.5" }, { "criteria": "cpe:2.3:o:motorola:android:4.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "62EFFAAF-F122-4019-8554-9E9CEF73CDAE" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:motorola:atrix_hd:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "75B24D97-F98A-4A1A-B20E-EB6D610C71EA" }, { "criteria": "cpe:2.3:h:motorola:razr_hd:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A5D2D0B7-8170-46F2-9FC8-2DDD3E96DE66" }, { "criteria": "cpe:2.3:h:motorola:razr_m:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "01FE07B3-068A-4C2A-A985-631070C17F51" }, { "criteria": "cpe:2.3:h:qualcomm:msm8960:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "73B9587B-78D0-4057-B694-E1E6655F624F" } ], "operator": "OR" } ], "operator": "AND" } ]