An integer overflow exists in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel prior to version 3.8.9. This vulnerability, notably present in certain Motorola builds of Android 4.1.2, allows a local attacker to exploit the /dev/graphics/fb0 device via crafted mmap2 system calls. The flaw enables the creation of a read-write memory mapping that spans the entirety of kernel memory, leading to privilege escalation. The vulnerability was exploited by the Motochopper pwn tool.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (POC) local exploit targeting Android devices, specifically leveraging the framebuffer device (/dev/graphics/fb0) to gain arbitrary kernel memory write capabilities. The main code is in 'fb_mem.c', which provides functions to map the framebuffer device into user space, calculate kernel physical offsets using /proc/iomem, and write arbitrary values to kernel addresses. The exploit is modular, exposing primitives for memory mapping and writing, and is intended to be used as a building block for privilege escalation or further kernel exploitation. The repository includes a Makefile for building a static library, a C source file implementing the exploit logic, and a header file defining the interface. No hardcoded payload is provided, but the code enables arbitrary kernel memory modification, which is a powerful exploitation primitive. The attack vector is local, requiring code execution on the target device with sufficient privileges to access the framebuffer device.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.