CVE-2016-5861
high
CVSS v3
8.8
CVSS v2
8.3
VIR risk
8.8
Description
In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable controlled by userspace is used to calculate offsets and sizes for copy operations, which could result in heap overflow.
Predictions
Exploit likelihood
82%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: product-security@qualcomm.com — https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=cf3c97b8b6165f13810e530068fbf94b07f1f77d
Vendor advisory: product-security@qualcomm.com — https://source.android.com/security/bulletin/2017-06-01
References
- http://www.securitytracker.com/id/1038623
- https://source.android.com/security/bulletin/2017-06-01
- https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=cf3c97b8b6165f13810e530068fbf94b07f1f77d
- http://www.securitytracker.com/id/1038623
- https://source.android.com/security/bulletin/2017-06-01
- https://source.codeaurora.org/quic/la//kernel/msm-4.4/commit/?id=cf3c97b8b6165f13810e530068fbf94b07f1f77d
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.