Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-3902. PoCs published by ScottyBauer.
AI-analyzed exploit summary This PoC exploits CVE-2016-3902, a vulnerability in the Android kernel's IPA driver, by sending a malformed ioctl request to /dev/wwan_ioctl with an invalid filter_index_list_len value (0xBADC0DE) and an invalid source_pipe_index (0xbeef), triggering a buffer overflow or memory corruption.
Description
drivers/platform/msm/ipa/ipa_qmi_service.c in the Qualcomm IPA driver in Android before 2016-10-05 on Nexus 5X and 6P devices allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 29953313 and Qualcomm internal bug CR 1044072.
Exploits (1)
This PoC exploits CVE-2016-3902, a vulnerability in the Android kernel's IPA driver, by sending a malformed ioctl request to /dev/wwan_ioctl with an invalid filter_index_list_len value (0xBADC0DE) and an invalid source_pipe_index (0xbeef), triggering a buffer overflow or memory corruption.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N