#VU41016 Permissions, Privileges, and Access Controls in Linux kernel - CVE-2014-4323
Published: December 12, 2014 / Updated: August 9, 2020
Linux kernel
Linux Foundation
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain start and length values within an ioctl call, which allows attackers to gain privileges via a crafted application.