CVE-2016-2059
published 2016-05-05CVE-2016-2059: The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm…
PriorityP430high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.21%
10.9th percentile
The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify that a port is a client port, which allows attackers to gain privileges or cause a denial of service (race condition and list corruption) by making many BIND_CONTROL_PORT ioctl calls.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | libidn | >= 0 < 1.28-1ubuntu2.1 | 1.28-1ubuntu2.1 |
| gnu | libidn | >= 0 < 1.32-3ubuntu1.1 | 1.32-3ubuntu1.1 |
| android | <= 7.0 | — | |
| android | — | — | |
| linux | linux_kernel | 3.0 – 3.19.8 | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-2059: Android Security Bulletin 2016-09-01
CVE: CVE-2016-2059
Severity: HIGH
References: A-27045580
QC-CR#974577
vendor_android·2016-09-01·CVSS 7.0
CVE-2016-2059 [HIGH] CVE-2016-2059: Android Security Bulletin 2016-09-01
CVE: CVE-2016-2059
Severity: HIGH
References: A-27045580
QC-CR#974577
Android Security Bulletin 2016-09-01
CVE: CVE-2016-2059
Severity: HIGH
References: A-27045580
QC-CR#974577
GHSA
GHSA-g893-8gjr-xqxv: The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core
ghsa_unreviewed·2022-05-13
CVE-2016-2059 [HIGH] CWE-269 GHSA-g893-8gjr-xqxv: The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core
The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify that a port is a client port, which allows attackers to gain privileges or cause a denial of service (race condition and list corruption) by making many BIND_CONTROL_PORT ioctl calls.
OSV
libidn vulnerabilities
osv·2016-08-24·CVSS 7.5
CVE-2015-2059 libidn vulnerabilities
libidn vulnerabilities
Thijs Alkemade, Gustavo Grieco, Daniel Stenberg, and Nikos
Mavrogiannopoulos discovered that Libidn incorrectly handled invalid UTF-8
characters. A remote attacker could use this issue to cause Libidn to
crash, resulting in a denial of service, or possibly disclose sensitive
memory. This issue only applied to Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2015-2059)
Hanno Böck discovered that Libidn incorrectly handled certain input. A
remote attacker could possibly use this issue to cause Libidn to crash,
resulting in a denial of service. (CVE-2015-8948, CVE-2016-6262,
CVE-2016-6261, CVE-2016-6263)
No detection rules found.
No public exploits indexed.
http://source.android.com/security/bulletin/2016-10-01.htmlhttp://www.securityfocus.com/bid/90230http://www.securitytracker.com/id/1035765https://us.codeaurora.org/cgit/quic/la/kernel/msm-3.18/commit/?id=9e8bdd63f7011dff5523ea435433834b3702398dhttps://www.codeaurora.org/projects/security-advisories/linux-ipc-router-binding-any-port-control-port-cve-2016-2059http://source.android.com/security/bulletin/2016-10-01.htmlhttp://www.securityfocus.com/bid/90230http://www.securitytracker.com/id/1035765https://us.codeaurora.org/cgit/quic/la/kernel/msm-3.18/commit/?id=9e8bdd63f7011dff5523ea435433834b3702398dhttps://www.codeaurora.org/projects/security-advisories/linux-ipc-router-binding-any-port-control-port-cve-2016-2059
2016-05-05
Published