Samsung Fimg2d FIMG2D_BITBLT_BLIT Ioctl Concurrency Flaw
Posted by deepcore on October 28, 2015 – 12:52 pm
The Samsung Graphics 2D driver (/dev/fimg2d) is accessible by unprivileged users/applications. It was found that the ioctl implementation for this driver contains a locking error which can lead to memory errors (such as use-after-free) due to a race condition.
Post a reply
You must be logged in to post a comment.