CVE-2016-8438
Description
Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android. Versions: Kernel 3.18. Android ID: A-31624565. References: QC-CR#1023638.
CWE
- (none)
Affected
- Google Inc. / Android — v=Kernel-3.18 [affected]
CVSS
- (none)
References
- https://source.android.com/security/bulletin/2017-01-01.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/95227 vdb-entry, x_refsource_BID
Source
cvelistV5-main/cves/2016/8xxx/CVE-2016-8438.json