In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or integer underflows. These could lead to escalation of privilege.
The bug is located in the store_upgrade and store_cmd functions of the file drivers/input/touchscreen/stm/ftm4_pdc.c. Due to the lack of input data boundary checking and the possibility of an integer underflow (CWE-191), an out-of-bounds write occurs (CWE-787). An attacker can provide specially crafted input data to the touchscreen handling subsystem, thereby triggering a write in an unauthorized area of kernel memory.
Successful exploitation of the vulnerability can lead to privilege escalation — an attacker can obtain elevated privileges on the device, potentially up to the operating system kernel level.
Apply patches available from the manufacturer according to references — Google Pixel security bulletin dated 2018-06-01 (https://source.android.com/security/bulletin/pixel/2018-06-01).
Devices running Google Android equipped with the STM FTM4 touchscreen driver (ftm4_pdc); specific system versions indicated in manufacturer references (Pixel security bulletin, June 2018).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGoogle Android
OSGoogleall versions
Related vulnerabilities
Heap buffer overflow w Google Chrome na Android — sandbox escape
Adobe Flash Player — RCE lub DoS przez nieokreślone wektory ataku
Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever...
Use after free in Sessions in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lev...
Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local at...