ID

VAR-201705-1958


CVE

CVE-2015-8089


TITLE

plural Huawei P7 Software GPU Vulnerability in driver to read / write arbitrary kernel memory area

Trust: 0.8

sources: JVNDB: JVNDB-2015-007568

DESCRIPTION

The GPU driver in Huawei P7 phones with software P7-L00 before P7-L00C17B851, P7-L05 before P7-L05C00B851, and P7-L09 before P7-L09C92B851 allows local users to read or write to arbitrary kernel memory locations and consequently cause a denial of service (system crash) or gain privileges via a crafted application. HuaweiP7 is a smartphone from China's Huawei company. GPUdriver is a graphics processor driver used in it. The GPU driver in HuaweiP7 has a privilege escalation vulnerability that stems from the GPU's failure to adequately verify the validity of incoming parameters. A local attacker can use this vulnerability to spoof a user to install a malicious application to read and modify the memory address of the product, causing a system crash or privilege escalation. Huawei P7 is prone to a local privilege-escalation vulnerability. Local attackers may exploit this issue to gain elevated privileges. The following versions are affected: Huawei P7 versions prior to P7-L00C17B851, versions prior to P7-L05C00B851, versions prior to P7-L09C92B851

Trust: 2.52

sources: NVD: CVE-2015-8089 // JVNDB: JVNDB-2015-007568 // CNVD: CNVD-2017-08782 // BID: 98623 // VULHUB: VHN-86050

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-08782

AFFECTED PRODUCTS

vendor:huaweimodel:p7-l09scope:eqversion: -

Trust: 1.6

vendor:huaweimodel:p7-l05scope:eqversion: -

Trust: 1.6

vendor:huaweimodel:p7-l00scope:eqversion: -

Trust: 1.6

vendor:huaweimodel:p7-l00scope:ltversion:p7-l00c17b851

Trust: 0.8

vendor:huaweimodel:p7-l05scope:ltversion:p7-l05c00b851

Trust: 0.8

vendor:huaweimodel:p7-l09scope:ltversion:p7-l09c92b851

Trust: 0.8

vendor:huaweimodel:p7 <p7-l00c17b851scope: - version: -

Trust: 0.6

vendor:huaweimodel:p7 <p7-l05c00b851scope: - version: -

Trust: 0.6

vendor:huaweimodel:p7scope:eqversion:0

Trust: 0.3

vendor:huaweimodel:p7 p7-l09c92b851scope:neversion: -

Trust: 0.3

vendor:huaweimodel:p7 p7-l05c00b851scope:neversion: -

Trust: 0.3

vendor:huaweimodel:p7 p7-l00c17b851scope:neversion: -

Trust: 0.3

sources: CNVD: CNVD-2017-08782 // BID: 98623 // JVNDB: JVNDB-2015-007568 // CNNVD: CNNVD-201705-1165 // NVD: CVE-2015-8089

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-8089
value: HIGH

Trust: 1.0

NVD: CVE-2015-8089
value: HIGH

Trust: 0.8

CNVD: CNVD-2017-08782
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201705-1165
value: MEDIUM

Trust: 0.6

VULHUB: VHN-86050
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-8089
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-08782
severity: MEDIUM
baseScore: 6.2
vectorString: AV:L/AC:H/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 1.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-86050
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2015-8089
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2017-08782 // VULHUB: VHN-86050 // JVNDB: JVNDB-2015-007568 // CNNVD: CNNVD-201705-1165 // NVD: CVE-2015-8089

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-86050 // JVNDB: JVNDB-2015-007568 // NVD: CVE-2015-8089

THREAT TYPE

local

Trust: 0.9

sources: BID: 98623 // CNNVD: CNNVD-201705-1165

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201705-1165

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-007568

PATCH

title:Huawei-SA-20151103-01-GPUurl:http://www.huawei.com/en/psirt/security-advisories/hw-460276

Trust: 0.8

title:HuaweiP7GPU Driver Licensing Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/94995

Trust: 0.6

title:Huawei P7 GPU Fixes for driver permission and access control vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=70537

Trust: 0.6

sources: CNVD: CNVD-2017-08782 // JVNDB: JVNDB-2015-007568 // CNNVD: CNNVD-201705-1165

EXTERNAL IDS

db:NVDid:CVE-2015-8089

Trust: 3.4

db:JVNDBid:JVNDB-2015-007568

Trust: 0.8

db:CNNVDid:CNNVD-201705-1165

Trust: 0.7

db:CNVDid:CNVD-2017-08782

Trust: 0.6

db:BIDid:98623

Trust: 0.4

db:VULHUBid:VHN-86050

Trust: 0.1

sources: CNVD: CNVD-2017-08782 // VULHUB: VHN-86050 // BID: 98623 // JVNDB: JVNDB-2015-007568 // CNNVD: CNNVD-201705-1165 // NVD: CVE-2015-8089

REFERENCES

url:http://www1.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-460276.htm

Trust: 2.3

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-8089

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2015-8089

Trust: 0.8

url:http://www.huawei.com

Trust: 0.3

url:http://www.huawei.com/en/psirt/security-advisories/hw-460276

Trust: 0.3

sources: CNVD: CNVD-2017-08782 // VULHUB: VHN-86050 // BID: 98623 // JVNDB: JVNDB-2015-007568 // CNNVD: CNNVD-201705-1165 // NVD: CVE-2015-8089

CREDITS

Hang Zhang/ Dongdong She/Zhiyun Qian from University of California, Riverside and by Yanfeng Wang/Chiachih Wu/ Xuxian Jiang of C0RE Team from Qihoo 360

Trust: 0.3

sources: BID: 98623

SOURCES

db:CNVDid:CNVD-2017-08782
db:VULHUBid:VHN-86050
db:BIDid:98623
db:JVNDBid:JVNDB-2015-007568
db:CNNVDid:CNNVD-201705-1165
db:NVDid:CVE-2015-8089

LAST UPDATE DATE

2025-04-20T23:27:24.916000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-08782date:2017-06-08T00:00:00
db:VULHUBid:VHN-86050date:2017-06-06T00:00:00
db:BIDid:98623date:2015-11-03T00:00:00
db:JVNDBid:JVNDB-2015-007568date:2017-06-26T00:00:00
db:CNNVDid:CNNVD-201705-1165date:2017-05-24T00:00:00
db:NVDid:CVE-2015-8089date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-08782date:2017-06-08T00:00:00
db:VULHUBid:VHN-86050date:2017-05-23T00:00:00
db:BIDid:98623date:2015-11-03T00:00:00
db:JVNDBid:JVNDB-2015-007568date:2017-06-26T00:00:00
db:CNNVDid:CNNVD-201705-1165date:2017-05-24T00:00:00
db:NVDid:CVE-2015-8089date:2017-05-23T04:29:01.070