Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2016-0821 Details

Description

The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in Android 6.0.1 before 2016-03-01, does not properly consider the relationship to the mmap_min_addr value, which makes it easier for attackers to bypass a poison-pointer protection mechanism by triggering the use of an uninitialized list entry, aka Android internal bug 26186802, a different vulnerability than CVE-2015-3636.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8a5e5e02fc83aaf67053ab53b359af08c6c49aaf CVEIssue TrackingPatchVendor Advisory
https://github.com/torvalds/linux/commit/8a5e5e02fc83aaf67053ab53b359af08c6c49aaf CVEIssue TrackingPatchThird Party Advisory
http://source.android.com/security/bulletin/2016-03-01.html CVEThird Party Advisory
http://www.debian.org/security/2016/dsa-3607 CVEThird Party Advisory
http://www.openwall.com/lists/oss-security/2015/05/02/6 CVEMailing ListThird Party Advisory

see all 30 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-908Use of Uninitialized Resource[email protected]

Affected Products

ProductVersions
linux linux kernel
< 4.3

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
google android
6.0.1

CPE

  • cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

9 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2016-0821
NVD Published Date:
Mar 12, 2016
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2016-0821 Details - Not Deferred