cbcvebase.
CVE-2016-5863
published 2017-08-16

CVE-2016-5863: In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to…

PriorityP432high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.55%
42.7th percentile
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.

Affected

4 ranges
VendorProductVersion rangeFixed in
googleandroid
linuxlinux_kernel>= 0 < 3.13.0-95.1423.13.0-95.142
linuxlinux_kernel>= 0 < 4.4.0-36.554.4.0-36.55
qualcomm_incall_qualcomm_products

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.