The msm_bus_dbg_update_request_write function in drivers/platform/msm/msm_bus/msm_bus_dbg.c in android_kernel_huawei_msm8916 through 2017-06-16 in LineageOS, and possibly other kernels for MSM devices, allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted /sys/kernel/debug/msm-bus-dbg/client-data/update-request write request.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://blog.secret-team.cn/index.php/archives/5/ | third party advisory |
http://www.securityfocus.com/bid/99107 | third party advisory vdb entry |