CVE-2016-2059 Details
Description
The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not verify that a port is a client port, which allows attackers to gain privileges or cause a denial of service (race condition and list corruption) by making many BIND_CONTROL_PORT ioctl calls.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.0, <= 3.19.8 |
CPE
Remediation
| |
| google android | <= 7.0 |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 3, 2020 | Modified Analysis | [email protected] |
| Dec 1, 2016 | CVE Modified | [email protected] |
| Nov 28, 2016 | CVE Modified | [email protected] |
| Oct 13, 2016 | Modified Analysis | [email protected] |
| Oct 13, 2016 | Initial Analysis | [email protected] |
| Oct 12, 2016 | CVE Modified | [email protected] |
| May 10, 2016 | Modified Analysis | [email protected] |
| May 9, 2016 | Initial Analysis | [email protected] |
| May 9, 2016 | Initial Analysis | [email protected] |