Vulnerability Description
Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android. Versions: Kernel 3.18. Android ID: A-31624565. References: QC-CR#1023638.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 3.18 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95227
- https://source.android.com/security/bulletin/2017-01-01.htmlVendor Advisory
- http://www.securityfocus.com/bid/95227
- https://source.android.com/security/bulletin/2017-01-01.htmlVendor Advisory
FAQ
What is CVE-2016-8438?
CVE-2016-8438 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android...
How severe is CVE-2016-8438?
CVE-2016-8438 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-8438?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.