CVE-2016-8438

Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android. Versions: Kernel 3.18. Android ID: A-31624565. References: QC-CR#1023638.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:3.18:*:*:*:*:*:*:*

History

21 Nov 2024, 02:59

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/95227 - () http://www.securityfocus.com/bid/95227 -
References () https://source.android.com/security/bulletin/2017-01-01.html - Vendor Advisory () https://source.android.com/security/bulletin/2017-01-01.html - Vendor Advisory

Information

Published : 2017-01-12 20:59

Updated : 2024-11-21 02:59


NVD link : CVE-2016-8438

Mitre link : CVE-2016-8438

CVE.ORG link : CVE-2016-8438


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-190

Integer Overflow or Wraparound