Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
Link | Tags |
---|---|
https://docs.qualcomm.com/product/publicresources/securitybulletin/november-2024-bulletin.html | patch vendor advisory |