CVE-2016-0821
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-pointer protection mechanism by triggering the use of an uninitialized list entry, aka Android internal bug 26186802, a different vulnerability than CVE-2015-3636.
La funcionalidad LIST_POISON en include/linux/poison.h en el kernel de Linux en versiones anteriores a 4.3, como se utiliza en Android 6.0.1 en versiones anteriores a 2016-03-01, no considera adecuadamente la relación del valor mmap_min_addr, lo que hace más fácil a atacantes eludir un mecanismo de protección poison-pointer desencadenando el uso de una entrada de lista no inicializada, también conocido como error interno de Android 26186802, una vulnerabilidad diferente a CVE-2015-3636.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-12-16 CVE Reserved
- 2016-03-12 CVE Published
- 2024-08-05 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-908: Use of Uninitialized Resource
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://source.android.com/security/bulletin/2016-03-01.html | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2015/05/02/6 | Mailing List | |
http://www.securityfocus.com/bid/84260 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2016/dsa-3607 | 2022-01-31 | |
http://www.ubuntu.com/usn/USN-2967-1 | 2022-01-31 | |
http://www.ubuntu.com/usn/USN-2967-2 | 2022-01-31 | |
http://www.ubuntu.com/usn/USN-2968-1 | 2022-01-31 | |
http://www.ubuntu.com/usn/USN-2968-2 | 2022-01-31 | |
http://www.ubuntu.com/usn/USN-2969-1 | 2022-01-31 | |
http://www.ubuntu.com/usn/USN-2970-1 | 2022-01-31 | |
http://www.ubuntu.com/usn/USN-2971-1 | 2022-01-31 | |
http://www.ubuntu.com/usn/USN-2971-2 | 2022-01-31 | |
http://www.ubuntu.com/usn/USN-2971-3 | 2022-01-31 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | < 4.3 Search vendor "Linux" for product "Linux Kernel" and version " < 4.3" | - |
Affected
| ||||||
Google Search vendor "Google" | Android Search vendor "Google" for product "Android" | 6.0.1 Search vendor "Google" for product "Android" and version "6.0.1" | - |
Affected
|