CVE-2016-5340
The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass intended access restrictions by using the /ashmem string as the dentry name.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- google/android · linux/linux kernel
- Source
- cve@mitre.org
References
- http://source.android.com/security/bulletin/2016-10-01.htmlThird Party Advisory
- http://www.securityfocus.com/bid/92374Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036763Third Party Advisory, VDB Entry
- https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=06e51489061e5473b4e2035c79dcf7c27a6f75a6Mailing List, Patch, Third Party Advisory
- https://www.codeaurora.org/invalid-path-check-ashmem-memory-file-cve-2016-5340Broken Link
- http://source.android.com/security/bulletin/2016-10-01.htmlThird Party Advisory
- http://www.securityfocus.com/bid/92374Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036763Third Party Advisory, VDB Entry
- https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=06e51489061e5473b4e2035c79dcf7c27a6f75a6Mailing List, Patch, Third Party Advisory
- https://www.codeaurora.org/invalid-path-check-ashmem-memory-file-cve-2016-5340Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.