CVE-2016-8440Improper Restriction of Operations within the Bounds of a Memory Buffer in INC Android

Severity
9.8CRITICALNVD
EPSS
0.5%
top 32.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 17

Description

Possible buffer overflow in SMMU system call. Improper input validation in ADSP SID2CB system call may result in hypervisor memory overwrite. Product: Android. Versions: Kernel 3.18. Android ID: A-31625306. References: QC-CR#1036747.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5google_inc/androidKernel-3.18

🔴Vulnerability Details

1
GHSA
GHSA-gxfv-4j87-2g8p: Possible buffer overflow in SMMU system call2022-05-17

📋Vendor Advisories

1
Android
CVE-2016-8440: Android Security Bulletin 2017-01-01 CVE: CVE-2016-8440 Severity: HIGH References: A-31625306**2017-01-01

📄Research Papers

1
arXiv
Towards Linux Kernel Memory Safety2017-10-17