CVE-2016-2062
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, uses an incorrect integer data type, which allows attackers to cause a denial of service (integer overflow, heap-based buffer overflow, and incorrect memory allocation) or possibly have unspecified other impact via a crafted IOCTL_KGSL_PERFCOUNTER_QUERY ioctl call.
La función adreno_perfcounter_query_group en drivers/gpu/msm/adreno_perfcounter.c en el controlador Adreno GPU para el kernel de Linux 3.x, según se utiliza en Qualcomm Innovation Center (QuIC) Android contributions for MSM devices y otros productos, utiliza un tipo de datos entero incorrecto, lo que permite a atacantes provocar una denegación de servicio (desbordamiento de entero, desbordamiento de buffer basado en memoria dinámica y asignación de memoria incorrecta) o posiblemente tener otro impacto no especificado a través de una llamada ioctl IOCTL_KGSL_PERFCOUNTER_QUERY.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-01-25 CVE Reserved
- 2016-05-05 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1035766 | Third Party Advisory | |
https://www.codeaurora.org/buffer-overflow-adreno-gpu-msm-driver-cve-2016-2062 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://source.android.com/security/bulletin/2016-06-01.html | 2020-08-03 | |
https://codeaurora.org/cgit/quic/la/kernel/msm-3.18/commit/?id=27c95b64b2e4b5ff1288cbaa6e353dd803d71576 | 2020-08-03 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Google Search vendor "Google" | Nexus 5x Firmware Search vendor "Google" for product "Nexus 5x Firmware" | - | - |
Affected
| in | Google Search vendor "Google" | Nexus 5x Search vendor "Google" for product "Nexus 5x" | - | - |
Safe
|
Google Search vendor "Google" | Nexus 6p Firmware Search vendor "Google" for product "Nexus 6p Firmware" | - | - |
Affected
| in | Google Search vendor "Google" | Nexus 6p Search vendor "Google" for product "Nexus 6p" | - | - |
Safe
|
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 3.0 <= 3.19.8 Search vendor "Linux" for product "Linux Kernel" and version " >= 3.0 <= 3.19.8" | - |
Affected
|