VULNERABILITY INTELLIGENCE
CVE-2016-8459
CVSS score9.8 CRITICAL
EPSS probability1.71%
CISA KEVNot currently listed
Published2017-01-12
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Possible buffer overflow in storage subsystem. Bad parameters as part of listener responses to RPMB commands could lead to buffer overflow. Product: Android. Versions: Kernel 3.18. Android ID: A-32577972. References: QC-CR#988462.
Weakness classification
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
Primary references
- security@android.com
- security@android.com — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory