Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral Image Loader) PIL authentication. Product: Android. Versions: Kernel 3.18. Android ID: A-31624565. References: QC-CR#1023638.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securityfocus.com/bid/95227 | |
| https://source.android.com/security/bulletin/2017-01-01.html | Vendor Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2017-01-12 20:59
Updated : 2017-01-18 02:59
NVD link : CVE-2016-8438
Mitre link : CVE-2016-8438
CVE.ORG link : CVE-2016-8438
JSON object : View
Products Affected
                linux
- linux_kernel
 
CWE
                
                    
                        
                        CWE-190
                        
            Integer Overflow or Wraparound
