HIGH · 7.8

CVE-2016-2062

The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contribution...

Vulnerability Description

The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, uses an incorrect integer data type, which allows attackers to cause a denial of service (integer overflow, heap-based buffer overflow, and incorrect memory allocation) or possibly have unspecified other impact via a crafted IOCTL_KGSL_PERFCOUNTER_QUERY ioctl call.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
LinuxLinux Kernel>= 3.0, <= 3.19.8
GoogleNexus 5X Firmware-
GoogleNexus 5X-
GoogleNexus 6P Firmware-
GoogleNexus 6P-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-2062?

CVE-2016-2062 is a vulnerability with a CVSS score of 7.8 (HIGH). The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contribution...

How severe is CVE-2016-2062?

CVE-2016-2062 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-2062?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Google Nexus 5X Firmware, Google Nexus 5X, Google Nexus 6P Firmware, Google Nexus 6P.