CVE-2016-5863 PUBLISHED

In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.

EPSS 0.05% · 16.9th percentile

Risk Scores

EPSS Score
0.05%
16.9th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:24.04:LTSlinux-gcp-6.116.11.0-1016.16~24.04.1, 6.11.0-1015.15~24.04.1, 6.11.0-1014.14~24.04.1
Ubuntu:20.04:LTSlinux-raspi25.4.0-1006.6, 5.3.0-1017.19, 5.4.0-1004.4
Ubuntu:24.04:LTSlinux-realtime6.8.1-1015.16, 0
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1020.23, 4.4.0-1015.18, 0
Ubuntu:24.04:LTSlinux-lowlatency-hwe-6.116.11.0-1009.10~24.04.1, 0, 6.11.0-1016.17~24.04.1
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1065.68+cvm2.1, 5.4.0-1067.70+cvm1.1, 5.4.0-1068.71+cvm1.1
Ubuntu:Pro:20.04:LTSlinux-azure-fde-5.155.15.0-1076.85~20.04.1.1, 5.15.0-1103.112~20.04.1.1, 5.15.0-1102.111~20.04.1.1
Ubuntu:16.04:LTSlinux4.4.0-18.34, 4.4.0-7.22, 4.4.0-8.23
Ubuntu:22.04:LTSlinux-riscv0, 5.13.0-1004.4, 5.13.0-1006.6+22.04.1
Ubuntu:20.04:LTSlinux-gke5.4.0-1084.90, 0, 5.4.0-1033.35
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:20.04:LTSlinux-gkeop5.4.0-1089.93, 5.4.0-1090.94, 5.4.0-1091.95
Ubuntu:14.04:LTSlinux-lts-xenial4.4.0-34.53~14.04.1, 4.4.0-31.50~14.04.1, 4.4.0-28.47~14.04.1
Ubuntu:24.04:LTSlinux-azure-6.116.11.0-1008.8~24.04.1, 0, 6.11.0-1012.12~24.04.1
Ubuntu:24.04:LTSlinux-hwe-6.116.11.0-19.19~24.04.1, 6.11.0-17.17~24.04.2, 6.11.0-29.29~24.04.1
Ubuntu:16.04:LTSlinux-raspi24.2.0-1014.21, 4.2.0-1013.19, 0
Ubuntu:14.04:LTSlinux3.13.0-63.103, 3.13.0-62.102, 3.13.0-61.100
Ubuntu:22.04:LTSlinux-intel-iot-realtime0, 5.15.0-1073.75
Ubuntu:24.04:LTSlinux-riscv6.8.0-39.39.1, 6.8.0-40.40.1, 6.8.0-41.41.1

…and 1 more

Timeline

References

Open in Interactive Console →