Huawei Frame Buffer Driver Arbitrary Memory Write
Description
Huawei is a company that provides networking and telecommunications equipment.
The MediaTek frame buffer driver, as shipped with Huawei Y6 Pro, implements an IOCTL interface vulnerable to an arbitrary memory write due to insufficient input validation.
Impact
Local processes running in the context of a system application, media server, or system server can leverage the frame buffer driver memory corruption to escalate their privileges to root or kernel.
Cause
The MediaTek frame buffer driver fails to validate user-supplied data.
Solution
This vulnerability was resolved by Huawei in version TIT-L01C576B119. More information can be found on the Huawei web page: http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170527-01-smartphone-en
Technical details
Please refer to the attached advisory.