CVE-2016-8439Improper Restriction of Operations within the Bounds of a Memory Buffer in INC Android

Severity
9.8CRITICALNVD
EPSS
0.6%
top 30.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 17

Description

Possible buffer overflow in trust zone access control API. Buffer overflow may occur due to lack of buffer size checking. Product: Android. Versions: Kernel 3.18. Android ID: A-31625204. References: QC-CR#1027804.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5google_inc/androidKernel-3.18

🔴Vulnerability Details

1
GHSA
GHSA-7342-qgvc-m343: Possible buffer overflow in trust zone access control API2022-05-17

📋Vendor Advisories

1
Android
CVE-2016-8439: Android Security Bulletin 2017-01-01 CVE: CVE-2016-8439 Severity: HIGH References: A-31625204**2017-01-01