Vulnerability in the v4l2 driver affecting the Android platform

TrendMicro released information about the vulnerability (CVE not assigned) in the driver v4l2, allowing a non-privileged local user to execute their code in the context of the Linux kernel. Details about the vulnerability are provided in the context of the Android platform, without specifying whether this issue is specific to the Android kernel or also occurs in the standard Linux kernel.

Exploitation of the vulnerability requires local access for the attacker to the system. In Android, for an attack to succeed, the attacker must first gain control over a non-privileged application that has access to the V4L (Video for Linux) subsystem, such as a camera-related application. The most realistic use of the vulnerability in Android involves embedding the exploit in malicious applications prepared by the attackers to escalate privileges on the device.

Currently, the vulnerability remains unpatched. Despite Google being notified of the issue in March, a fix has not been included in the September update for the Android platform. The September security patch set for Android addresses 49 vulnerabilities, four of which have been assigned a critical severity level. Two critical vulnerabilities have been fixed in the multimedia framework, allowing code execution when processing specially crafted multimedia data. 31 vulnerabilities have been fixed in components for Qualcomm chips, two of which have been assigned critical severity, allowing for remote attack. The remaining issues are marked as dangerous, meaning they allow for code execution in the context of a privileged process through manipulation of local applications.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster