PT-2017-1224 · Google+4 · Android+4
Published
2016-12-29
·
Updated
2024-04-02
·
CVE-2016-8399
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions Kernel-3.10 through Kernel-3.18
Description
An elevation of privilege issue in the kernel networking subsystem could allow a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and current compiler optimizations restrict access to the vulnerable code.
Recommendations
For versions Kernel-3.10 through Kernel-3.18, consider restricting access to the kernel networking subsystem until a patch is available.
As a temporary workaround, consider disabling any functionality that relies on the vulnerable kernel networking subsystem to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Centos
Red Hat
Suse
Ubuntu