CVE-2016-5340
published 2016-08-07CVE-2016-5340: The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.7th percentile
The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass intended access restrictions by using the /ashmem string as the dentry name.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| android | <= 7.0 | — | |
| android | — | — | |
| linux | linux_kernel | 3.0 – 3.19.8 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-5340: Android Security Bulletin 2016-09-01
CVE: CVE-2016-5340
Severity: CRITICAL
References: A-30652312
QC-CR#1008948
vendor_android·2016-09-01·CVSS 7.8
CVE-2016-5340 [HIGH] CVE-2016-5340: Android Security Bulletin 2016-09-01
CVE: CVE-2016-5340
Severity: CRITICAL
References: A-30652312
QC-CR#1008948
Android Security Bulletin 2016-09-01
CVE: CVE-2016-5340
Severity: CRITICAL
References: A-30652312
QC-CR#1008948
Debian
CVE-2016-5340: linux - The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qua...
vendor_debian·2016·CVSS 7.8
CVE-2016-5340 [HIGH] CVE-2016-5340: linux - The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qua...
The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass intended access restrictions by using the /ashmem string as the dentry name.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-622x-gpp9-6rc3: The is_ashmem_file function in drivers/staging/android/ashmem
ghsa_unreviewed·2022-05-13
CVE-2016-5340 [HIGH] CWE-20 GHSA-622x-gpp9-6rc3: The is_ashmem_file function in drivers/staging/android/ashmem
The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass intended access restrictions by using the /ashmem string as the dentry name.
OSV
CVE-2016-5340: The is_ashmem_file function in drivers/staging/android/ashmem
osv·2016-08-07·CVSS 7.8
CVE-2016-5340 [HIGH] CVE-2016-5340: The is_ashmem_file function in drivers/staging/android/ashmem
The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass intended access restrictions by using the /ashmem string as the dentry name.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-10-01.htmlhttp://www.securityfocus.com/bid/92374http://www.securitytracker.com/id/1036763https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=06e51489061e5473b4e2035c79dcf7c27a6f75a6https://www.codeaurora.org/invalid-path-check-ashmem-memory-file-cve-2016-5340http://source.android.com/security/bulletin/2016-10-01.htmlhttp://www.securityfocus.com/bid/92374http://www.securitytracker.com/id/1036763https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=06e51489061e5473b4e2035c79dcf7c27a6f75a6https://www.codeaurora.org/invalid-path-check-ashmem-memory-file-cve-2016-5340
2016-08-07
Published