CVE-2016-8459Improper Restriction of Operations within the Bounds of a Memory Buffer in INC Android

Severity
9.8CRITICALNVD
EPSS
0.6%
top 30.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 17

Description

Possible buffer overflow in storage subsystem. Bad parameters as part of listener responses to RPMB commands could lead to buffer overflow. Product: Android. Versions: Kernel 3.18. Android ID: A-32577972. References: QC-CR#988462.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5google_inc/androidKernel-3.18

🔴Vulnerability Details

1
GHSA
GHSA-rpgp-phpx-5cfv: Possible buffer overflow in storage subsystem2022-05-17

📋Vendor Advisories

1
Android
CVE-2016-8459: Android Security Bulletin 2017-01-01 CVE: CVE-2016-8459 Severity: HIGH References: A-32577972**2017-01-01

📄Research Papers

1
arXiv
Towards Linux Kernel Memory Safety2017-10-17