CVE-2016-4038

Published on: 02/01/2017 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:26:57 PM UTC

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Certain versions of Apq8084 from Samsung contain the following vulnerability:

Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/msm/camera_v2/sensor/msm_sensor.c in Samsung devices with Android KK(4.4) or L and an APQ8084, MSM8974, or MSM8974pro chipset allows local users to have unspecified impact via the gpio_config.gpio_name value.

  • CVE-2016-4038 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7.8 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
LOCAL LOW LOW NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVSS2 Score: 7.2 - HIGH

Access
Vector
Access
Complexity
Authentication
LOCAL LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
COMPLETE COMPLETE COMPLETE

CVE References

Description Tags Link
oss-security - Re: CVE request - samsumg android phone msm_sensor_config function write some range kernel address with any value Mailing List
Third Party Advisory
www.openwall.com
text/html
URL Logo MLIST [oss-security] 20160418 Re: CVE request - samsumg android phone msm_sensor_config function write some range kernel address with any value
oss-security - CVE request - samsumg android phone msm_sensor_config function write some range kernel address with any value Mailing List
Third Party Advisory
www.openwall.com
text/html
URL Logo MLIST [oss-security] 20160418 CVE request - samsumg android phone msm_sensor_config function write some range kernel address with any value
Samsung Mobile Security Blog Vendor Advisory
security.samsungmobile.com
text/html
URL Logo CONFIRM security.samsungmobile.com/smrupdate.html#SMR-JAN-2016

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
HardwareSamsungApq8084-AllAllAll
HardwareSamsungApq8084-AllAllAll
HardwareSamsungMsm8974-AllAllAll
HardwareSamsungMsm8974-AllAllAll
HardwareSamsungMsm8974pro-AllAllAll
HardwareSamsungMsm8974pro-AllAllAll
Operating
System
SamsungSamsung Mobile4.4AllAllAll
Operating
System
SamsungSamsung Mobile5.0AllAllAll
Operating
System
SamsungSamsung Mobile5.1AllAllAll
Operating
System
SamsungSamsung Mobile4.4AllAllAll
Operating
System
SamsungSamsung Mobile5.0AllAllAll
Operating
System
SamsungSamsung Mobile5.1AllAllAll
  • cpe:2.3:h:samsung:apq8084:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:samsung:apq8084:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:samsung:msm8974:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:samsung:msm8974:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:samsung:msm8974pro:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:samsung:msm8974pro:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:samsung:samsung_mobile:4.4:*:*:*:*:*:*:*:
  • cpe:2.3:o:samsung:samsung_mobile:5.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:samsung:samsung_mobile:5.1:*:*:*:*:*:*:*:
  • cpe:2.3:o:samsung:samsung_mobile:4.4:*:*:*:*:*:*:*:
  • cpe:2.3:o:samsung:samsung_mobile:5.0:*:*:*:*:*:*:*:
  • cpe:2.3:o:samsung:samsung_mobile:5.1:*:*:*:*:*:*:*: