CVE-2016-8437
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
Improper input validation in Access Control APIs. Access control API may return memory range checking incorrectly. Product: Android. Versions: Kernel 3.18. Android ID: A-31623057. References: QC-CR#1009695.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security@android.com — https://source.android.com/security/bulletin/2017-01-01.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| linux-kernel | 3.18 | affected | |
References
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.