Samsung Fimg2d FIMG2D_BITBLT_BLIT Ioctl Concurrency Flaw

The Samsung Graphics 2D driver (/dev/fimg2d) is accessible by unprivileged users/applications. It was found that the ioctl implementation for this driver contains a locking error which can lead to memory errors (such as use-after-free) due to a race condition.

Leave a Reply