CVE-2016-2062

HIGH

Linux Kernel 3.0-3.19.8 - Denial of Service via Adreno GPU Driver IOCTL_KGSL_PERFCOUNTER_QUERY

Title source: llm
STIX 2.1

Description

The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, uses an incorrect integer data type, which allows attackers to cause a denial of service (integer overflow, heap-based buffer overflow, and incorrect memory allocation) or possibly have unspecified other impact via a crafted IOCTL_KGSL_PERFCOUNTER_QUERY ioctl call.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035766
Patch, Vendor Advisory x_refsource_confirm
http://source.android.com/security/bulletin/2016-06-01.html

Scores

CVSS v3 7.8
EPSS 0.0021
EPSS Percentile 10.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (3)
google/nexus_5x_firmware
google/nexus_6p_firmware
linux/linux_kernel 3.0 - 3.19.8
Published May 05, 2016
Tracked Since Feb 18, 2026