CVE-2017-6274
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
An elevation of Privilege vulnerability exists in the Thermal Driver, where a missing bounds checks in the thermal throttle driver can cause an out-of-bounds write in the kernel. This issue is rated as moderate. Product: Pixel. Version: N/A. Android ID: A-34705801. References: N-CVE-2017-6274.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@nvidia.com — https://source.android.com/security/bulletin/pixel/2017-11-01#announcements
References
CWEs
CWE-119
Verify integrity in audit chain (admin only). AS-IS.