CVE-2015-0569
high
CVSS v3
7.8
CVSS v2
9.3
VIR risk
7.8
Description
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka Wi-Fi) driver for the Linux kernel 3.x and 4.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via a crafted application that establishes a packet filter.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://source.android.com/security/bulletin/2016-05-01.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| linux-kernel | affected | |
References
- http://source.android.com/security/bulletin/2016-05-01.html
- http://www.securityfocus.com/bid/77691
- https://www.codeaurora.org/projects/security-advisories/multiple-issues-wlan-driver-allow-local-privilege-escalation-cve-2015
- https://www.exploit-db.com/exploits/39308/
- http://source.android.com/security/bulletin/2016-05-01.html
- http://www.securityfocus.com/bid/77691
- https://www.codeaurora.org/projects/security-advisories/multiple-issues-wlan-driver-allow-local-privilege-escalation-cve-2015
- https://www.exploit-db.com/exploits/39308/
CWEs
CWE-787
Verify integrity in audit chain (admin only). AS-IS.