CVE-2016-3856
netd in Android before 2016-08-05 mishandles tethering and stdio streams, which allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR959631.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
netd in Android before 2016-08-05 mishandles tethering and stdio streams, which allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted application, aka Qualcomm internal bug CR959631.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.47% probability · 40th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- google/android
- Source
- security@android.com
References
- http://source.android.com/security/bulletin/2016-08-01.htmlVendor Advisory
- http://www.securityfocus.com/bid/92256
- https://source.codeaurora.org/quic/la/platform/system/netd/commit/?h=LA.BF64.1.2.1&id=cc2853e6cec8ca2cf92430ad9a83358b131fc417Issue Tracking, Patch
- https://source.codeaurora.org/quic/la/platform/system/netd/commit/?h=LA.BR.1&id=568ef402f6d5a7a50c126aafc78c4edf59abba1cIssue Tracking, Patch
- http://source.android.com/security/bulletin/2016-08-01.htmlVendor Advisory
- http://www.securityfocus.com/bid/92256
- https://source.codeaurora.org/quic/la/platform/system/netd/commit/?h=LA.BF64.1.2.1&id=cc2853e6cec8ca2cf92430ad9a83358b131fc417Issue Tracking, Patch
- https://source.codeaurora.org/quic/la/platform/system/netd/commit/?h=LA.BR.1&id=568ef402f6d5a7a50c126aafc78c4edf59abba1cIssue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.