Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android. Versions: Kernel 3.18. Android ID: A-31624565. References: QC-CR#1023638.
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/2017-01-01.html | Vendor Advisory |
http://www.securityfocus.com/bid/95227 |
Configurations
Information
Published : 2017-01-12 12:59
Updated : 2017-01-17 18:59
NVD link : CVE-2016-8438
Mitre link : CVE-2016-8438
JSON object : View
CWE
CWE-190
Integer Overflow or Wraparound
Products Affected
linux
- linux_kernel