CVE-2016-8764 describes an input validation vulnerability in the TrustZone driver of specific Huawei P9, P9 Lite, and P8 Lite phone models. This flaw allows high-privileged attackers to read and write user-mode memory data within the TrustZone driver. Rated Medium severity (CVSS 6.4), exploitation requires high attack complexity and high privileges, but could lead to complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:huawei:p9_firmware:-:*:*:*:*:*:*:* | ||
<= vns-l21c185b130CPE matchmatch criteria | cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* | ||
<= ale-l02c636b150CPE matchmatch criteria | cpe:2.3:o:huawei:p8_lite_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.