CVE-2016-10239
In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper input validation an integer overflow vulnerability leading to a buffer overflow could potentially occur and a buffer…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper input validation an integer overflow vulnerability leading to a buffer overflow could potentially occur and a buffer over-read vulnerability could potentially occur.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.70% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-190
- Affected
- google/android
- Source
- security@android.com
References
- http://www.securityfocus.com/bid/97334Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038201
- https://source.android.com/security/bulletin/2017-04-01Patch, Vendor Advisory
- http://www.securityfocus.com/bid/97334Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038201
- https://source.android.com/security/bulletin/2017-04-01Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.