CVE-2016-2062
Summary
| CVE | CVE-2016-2062 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-05-05 21:59:00 UTC |
| Updated | 2020-08-03 16:03:00 UTC |
| Description | The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, uses an incorrect integer data type, which allows attackers to cause a denial of service (integer overflow, heap-based buffer overflow, and incorrect memory allocation) or possibly have unspecified other impact via a crafted IOCTL_KGSL_PERFCOUNTER_QUERY ioctl call. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Nexus 5x | - | All | All | All | |
| Hardware | Nexus 5x | - | All | All | All | |
| Operating System | Nexus 5x Firmware | - | All | All | All | |
| Operating System | Nexus 5x Firmware | - | All | All | All | |
| Hardware | Nexus 6p | - | All | All | All | |
| Hardware | Nexus 6p | - | All | All | All | |
| Operating System | Nexus 6p Firmware | - | All | All | All | |
| Operating System | Nexus 6p Firmware | - | All | All | All | |
| Operating System | Linux | Linux Kernel | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Android Adreno GPU Driver Buffer Overflow Lets Local Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| kernel/msm-3.18 - Unnamed repository; edit this file 'description' to name the repository. | CONFIRM | codeaurora.org | Mailing List, Patch, Third Party Advisory |
| Android Security Bulletin—June 2016 | Android Open Source Project | CONFIRM | source.android.com | Patch, Vendor Advisory |
| Page not found - Code Aurora | CONFIRM | www.codeaurora.org | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.