vendor:
Exynos Seiren Audio Driver
by:
Google Security Research
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Exynos Seiren Audio Driver
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:samsung:exynos_seiren_audio_driver
Platforms Tested: Android (Samsung S6 Edge)
Exynos Seiren Audio Driver Buffer Overflow Vulnerability
The Exynos Seiren Audio driver has a buffer overflow vulnerability in the write() implementation, allowing for memory corruption. The vulnerability can be triggered by writing to the device endpoint (/dev/seiren) with a user-supplied buffer that is not adequately bounds checked.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the patch provided by the vendor or update to a non-vulnerable version of the Exynos Seiren Audio driver. Additionally, access to the vulnerable device endpoint should be restricted to trusted users only.