Intel GPU VP9 Decoder Mem Access via Frame Size Fault
CVE-2017-11076 Published on November 26, 2024
Use of Out-of-range Pointer Offset in Video
On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder.
Vulnerability Analysis
CVE-2017-11076 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is an Untrusted pointer offset Vulnerability?
The program performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
CVE-2017-11076 has been classified to as an Untrusted pointer offset vulnerability or weakness.
Products Associated with CVE-2017-11076
Want to know whenever a new CVE is published for Intel Graphics Driver? stack.watch will email you.
Affected Versions
Qualcomm, Inc. Snapdragon:- Version MSM8909W is affected.
- Version MSM8996AU is affected.
- Version SD 210/SD 212/SD 205 is affected.
- Version SD 425 is affected.
- Version SD 427 is affected.
- Version SD 430 is affected.
- Version SD 435 is affected.
- Version SD 450 is affected.
- Version SD 615/16/SD 415 is affected.
- Version SD 625 is affected.
- Version SD 810 is affected.
- Version SD 820 is affected.
- Version SD 820A is affected.
- Version SD 835 is affected.
- Version SD 845 is affected.
- Version SDM429 is affected.
- Version SDM439 is affected.
- Version SDM630 is affected.
- Version SDM632 is affected.
- Version SDM636 is affected.
- Version SDM660 is affected.
- Version SDM710 is affected.
- Version Snapdragon_High_Med_2016 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.