CVE-2016-2059

The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify that a port is a client port, which allows attackers to gain privileges or cause a denial of service (race condition and list corruption) by making many BIND_CONTROL_PORT ioctl calls.
Configurations

Configuration 1 (hide)

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:google:android:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2016-05-05 21:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-2059

Mitre link : CVE-2016-2059

CVE.ORG link : CVE-2016-2059


JSON object : View

Products Affected

linux

  • linux_kernel

google

  • android
CWE
CWE-269

Improper Privilege Management