Bug 1396670 (CVE-2016-9278) - CVE-2016-9278 kernel: Kernel Crash on /dev/fimg2d ioctl command
Summary: CVE-2016-9278 kernel: Kernel Crash on /dev/fimg2d ioctl command
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2016-9278
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1396671
Blocks: 1394822
TreeView+ depends on / blocked
 
Reported: 2016-11-18 22:42 UTC by Adam Mariš
Modified: 2021-02-17 03:01 UTC (History)
34 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2016-11-28 05:47:11 UTC
Embargoed:


Attachments (Terms of Use)

Description Adam Mariš 2016-11-18 22:42:21 UTC
The fimg2d which is one of the graphic devices for Exynos chipsets doesn’t have exception control routines to handle unexpected commands and it can lead to kernel panic. The patch prevents kernel panic by ignoring inappropriate commands at the state.

CVE assignment:

http://seclists.org/oss-sec/2016/q4/405

External References:

http://security.samsungmobile.com/smrupdate.html#SMR-NOV-2016

Comment 1 Adam Mariš 2016-11-18 22:43:56 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 1396671]

Comment 2 Justin M. Forbes 2016-11-21 17:43:45 UTC
Not sure why we have a bug on this, the driver in question is in an upstream android tree at google, but not in Linus' linux kernel tree. Fedora doesn't ship this driver.

Comment 3 Wade Mealing 2016-11-28 05:47:11 UTC
Righto, will close that up.  There was enough CONFIG_EXYNO in the fedora kernels that it was affected.


Note You need to log in before you can comment on or make changes to this bug.