CVE-2016-2059 is a privilege escalation and denial-of-service vulnerability affecting the IPC router kernel module in Linux kernel 3.x, specifically within Qualcomm Innovation Center (QuIC) Android contributions for MSM devices. An attacker can exploit a race condition by repeatedly calling BIND_CONTROL_PORT ioctl, leading to list corruption. Rated 7.0 HIGH, this vulnerability has a local attack vector with high impact on confidentiality, integrity, and availability, but high attack complexity. While no public exploit code is available and it's not on the KEV catalog, it garnered significant community discussion and media coverage, notably as part of the "QuadRooter" vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, <= 3.19.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
<= 7.0CPE matchmatch criteria | cpe:2.3:o:google:android:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.