CVE-2016-8431

HIGH

Android Kernel 3.18 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-8431. PoCs published by codecat007.

AI-analyzed exploit summary The PoC exploits a vulnerability in the NVIDIA Tegra DRM driver by submitting crafted IOCTL commands to trigger a use-after-free or memory corruption, leading to local privilege escalation. It interacts with the DRM device to manipulate command buffers and relocations.

Description

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-32402179. References: N-CVE-2016-8431.

Exploits (1)

github WORKING POC 8 stars
by codecat007 · cpoc
https://github.com/codecat007/cvehub/tree/main/android/securityPatch/CVE-2016-8431

The PoC exploits a vulnerability in the NVIDIA Tegra DRM driver by submitting crafted IOCTL commands to trigger a use-after-free or memory corruption, leading to local privilege escalation. It interacts with the DRM device to manipulate command buffers and relocations.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: NVIDIA Tegra DRM driver (Android kernel)
No auth needed
Prerequisites: Access to the target device's DRM render node (/dev/dri/renderD129) · Kernel with vulnerable NVIDIA Tegra DRM driver
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95236

Scores

CVSS v3 7.8
EPSS 0.0023
EPSS Percentile 45.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (2)
Google Inc./Android Kernel-3.18
linux/linux_kernel 3.18
Published Jan 12, 2017
Tracked Since Feb 18, 2026