CVE-2016-6736
published 2016-11-25CVE-2016-6736: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary…
PriorityP337high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.65%
47.0th percentile
An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30953284. References: NVIDIA N-CVE-2016-6736.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | <= 7.0 | — | |
| android | — | — | |
| google_inc | android | — | — |
| klibc_project | klibc | >= 0 < 2.0.13-4ubuntu0.1 | 2.0.13-4ubuntu0.1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
klibc vulnerabilities
osv·2024-05-23·CVSS 8.8
CVE-2016-9840 klibc vulnerabilities
klibc vulnerabilities
USN-6736-1 fixed vulnerabilities in klibc. This update provides the
corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that zlib, vendored in klibc, incorrectly handled pointer
arithmetic. An attacker could use this issue to cause klibc to crash or to
possibly execute arbitrary code. (CVE-2016-9840, CVE-2016-9841)
Danilo Ramos discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain deflating operations. An attacker could use
this issue to cause klibc to crash or to possibly execute arbitrary code.
(CVE-2018-25032)
Evgeny Legerov discovered that zlib, vendored in klibc, incorrectly handled
memory when performing certain inflate operations. An attacker could use
this issue to cause klibc to c
GHSA
GHSA-5pvf-hchr-gwvf: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute ar
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2016-6736 [HIGH] GHSA-5pvf-hchr-gwvf: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute ar
An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30953284. References: NVIDIA N-CVE-2016-6736.
OSV
CVE-2016-6736: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute ar
osv·2016-11-25·CVSS 7.8
CVE-2016-6736 [HIGH] CVE-2016-6736: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute ar
An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30953284. References: NVIDIA N-CVE-2016-6736.
Red Hat
kernel: Kernel Crash on /dev/fimg2d ioctl command
vendor_redhat·2016-11-09·CVSS 5.5
CVE-2016-9278 [MEDIUM] CWE-391 kernel: Kernel Crash on /dev/fimg2d ioctl command
kernel: Kernel Crash on /dev/fimg2d ioctl command
The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Android
CVE-2016-6736: Android Security Bulletin 2016-11-01
CVE: CVE-2016-6736
Severity: CRITICAL
References: A-30953284*
N-CVE-2016-6736
vendor_android·2016-11-01·CVSS 7.8
CVE-2016-6736 [HIGH] CVE-2016-6736: Android Security Bulletin 2016-11-01
CVE: CVE-2016-6736
Severity: CRITICAL
References: A-30953284*
N-CVE-2016-6736
Android Security Bulletin 2016-11-01
CVE: CVE-2016-6736
Severity: CRITICAL
References: A-30953284*
N-CVE-2016-6736
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-11-25
Published